Knight Office Phishing Kit Steals Microsoft 365 Logins Without Touching Passwords
A new phishing kit called 'Knight Office' is targeting Microsoft 365 accounts by stealing active login sessions, rather than passwords. This technique allows attackers to bypass multi-factor authentication (MFA) and gain access to compromised accounts without ever needing to guess or crack a password.
Huntress researchers discovered the phishing kit after investigating suspicious sign-in activity on a customer's Microsoft 365 account in August. The attack begins with a fake email that appears to be a DocuSign signature request, complete with an urgent subject line pressuring the recipient to act.
Clicking the link in the email sends victims through a chain of redirects, including via the legitimate Monday.com work-management platform and a compromised Joomla website. Victims are then presented with what looks like a normal 'device login' code, mimicking the legitimate process Microsoft uses to sign into apps on other devices.
Once a victim enters the code and completes the Microsoft login, including approving the MFA prompt on their phone, exactly as they would for a genuine sign-in, the attacker's infrastructure silently intercepts and captures their live session. This stolen session is instantly usable, letting the attacker access the account as though they were the legitimate user.
The attackers didn't stop at the initial break-in, however. After gaining access, they registered a rogue device against the victim's Microsoft Entra ID (formerly Azure AD) tenant and bound a Windows Hello for Business passwordless credential to the compromised account.