US and EU Firms Hit with Widespread Microsoft 365 Session Hijacking
A wave of cyberattacks swept across the US and Europe in August, targeting businesses with Microsoft 365 session hijacking and remote management tool abuse.
Security researchers tracked campaigns that combined account takeover, persistent remote access, and credential theft. The attacks often disguised as legitimate activity, making detection difficult without behavioral analysis.
One phishing operation, highlighted in ANY.RUN's August cyberattack analysis, spanned 46 countries, with nearly half of observed activity tied to the United States. Attackers used fake tax notices, invoices, and shipping documents to trick victims into installing signed remote management tools such as ScreenConnect, ConnectWise, and LogMeIn Rescue.
A large-scale phishing-as-a-service kit called Mirage2FA compromised more than 4,000 US victims by intercepting credentials, MFA codes, and session cookies through adversary-in-the-middle techniques. This allowed attackers to hijack active Microsoft 365 sessions even after users completed multi-factor authentication.