HomeCyber BalkansNew Knight Office Phishing Kit Captures Microsoft 365 Logins Without Passwords

New Knight Office Phishing Kit Captures Microsoft 365 Logins Without Passwords

Published on

spot_img

New Phishing-as-a-Service Kit Threatens Microsoft 365 Accounts

Recent findings from cybersecurity firm Huntress reveal an emerging phishing-as-a-service kit, termed “Knight Office,” that is exploiting vulnerabilities in Microsoft 365 accounts. This kit employs a novel approach by hijacking active login sessions instead of simply stealing user passwords. Such a method allows attackers to bypass multi-factor authentication (MFA) without the need to crack, guess, or otherwise circumvent it, representing a significant escalation in cybersecurity threats.

The Knight Office kit was uncovered during an investigation by Huntress’s Security Operations Centre, initiated after suspicious sign-in activity was detected on a customer’s Microsoft 365 account in August. As researchers traced the source of the intrusion, they discovered a sophisticated operator console belonging to the attackers. This dashboard, created with a user-friendly design, incorporates features such as a Cloudflare Turnstile bot-check and real-time visitor statistics, all aimed at managing compromised accounts and stolen credentials from a centralized interface.

Huntress has been careful to differentiate between this operator panel and the actual phishing kit code itself. The former provides attackers with a comprehensive view of victims and their compromised data, while the latter is responsible for creating deceptive login pages used to fool unsuspecting targets.

Understanding the Attack Mechanism

The initial phase of this phishing campaign begins with the dissemination of a fake email crafted to resemble a DocuSign signature request. These emails feature urgent subject lines that compel recipients to take immediate action. In a particularly manipulative tactic, the emails are "self-spoofed," making it seem as though they are sent from the recipients’ own email addresses.

When recipients click on the embedded links, they are directed through a series of redirects, including a legitimate website, Monday.com, and a compromised Joomla site, misleading email security filters about the final destination. Eventually, victims arrive at a convincing imitation of a Microsoft login page, where they are prompted for a "device login" code—a step that echoes the legitimate Microsoft sign-in process.

Upon entering the code and completing the login, including approving any MFA prompts sent to their mobile devices, the attackers’ infrastructure discreetly captures the session. This stolen session allows the attackers to operate within the account as if they were the genuine user, entirely bypassing the need for passwords or MFA prompts.

Huntress’s telemetry indicated that the stolen tokens are reused via data center hosting infrastructure. Curiously, since no passwords were entered incorrectly, traditional alerts designed to flag password-related attempts went undetected.

A Long-Term Attack Strategy

The investigation by Huntress revealed that the attackers did not cease their operations at the initial breach. Following access to the victim’s account, they registered a rogue device within the victim’s Microsoft Entra ID (previously Azure AD) and linked it to a Windows Hello for Business (WHfB) passwordless credential. This tactic effectively created a backdoor, enabling the attackers to re-enter the account even after the compromised session was validated.

The researchers highlighted how this methodology cleverly transforms security features, initially designed to protect legitimate users, into mechanisms for attacker persistence.

Widespread Implications of the Campaign

Huntress noted that the same operator console is associated with at least nine confirmed phishing attacks targeting Microsoft 365 and Google Workspace accounts over a two-week span. Furthermore, management data reveals that more than 700 emails employing similar lures have been reported since April, indicating that this campaign has been running on a much larger scale for several months.

Different variants of the subject lines analyzed by researchers feature strategies like disguising as voicemail notifications or shared document alerts. Some variants notably substitute the letter “l” with “i” within key terms—such as “Important” and “Signature”—as a method to evade spam filters that rely on detecting exact keyword matches.

Shifts in Phishing Tactics

Knight Office is a part of a broader trend in phishing tactics, as tracked by Huntress, focusing on the theft of session tokens or OAuth access tokens instead of traditional credentials. Similar kits, like EvilTokens and Kali365, have been documented with comparable strategies. Researchers warn that such adversary-in-the-middle (AiTM) phishing attacks are becoming increasingly prevalent, as they significantly diminish the effectiveness of conventional password hygiene and MFA as standalone defenses.

Huntress recommends organizations shift their focus from merely identifying failed login attempts or standard password-spray alerts to monitoring unexpected post-MFA authentication events from unfamiliar devices. Furthermore, they advise careful review of newly registered Entra ID devices and WHfB credentials while promptly revoking any unauthorized authentication methods discovered.

Indicators of Compromise

To assist in identifying potential threats, Huntress has released a comprehensive list of indicators of compromise related to the Knight Office campaign. This includes the IP address of the phishing control panel (104.37.188[.]94), the domain hosting the control panel (idoej[.]com), and numerous lookalike phishing domains utilizing the .vu top-level domain.

The significance of such findings cannot be understated, as organizations and individuals continue to be targets for increasingly sophisticated phishing endeavors. As the landscape of cybersecurity threats evolves, staying informed and vigilant becomes paramount.

Source link

Latest articles

CISO vs. CSO: A New Perspective on Cybersecurity Leadership

The evolution of the roles within an organization's cybersecurity framework is increasingly positioned as...

International Operation Disrupts Sality P2P Botnet

Major Disruption of Long-Running P2P Botnet Sality In a groundbreaking enforcement operation orchestrated by U.S....

Polygon Patches Validator Security Vulnerabilities

Polygon Labs Effectively Addresses Security Vulnerabilities with Strategic Upgrades Polygon Labs has recently announced significant...

Government Information Security News, Training, and Education

Subscription Preferences: A Comprehensive Guide In a world where information is as precious as gold,...

More like this

CISO vs. CSO: A New Perspective on Cybersecurity Leadership

The evolution of the roles within an organization's cybersecurity framework is increasingly positioned as...

International Operation Disrupts Sality P2P Botnet

Major Disruption of Long-Running P2P Botnet Sality In a groundbreaking enforcement operation orchestrated by U.S....

Polygon Patches Validator Security Vulnerabilities

Polygon Labs Effectively Addresses Security Vulnerabilities with Strategic Upgrades Polygon Labs has recently announced significant...