Attackers compromise Wi-Fi gateways on travel networks to steal Microsoft 365 accounts via DNS redirection — an attack surface below endpoint visibility with potential for account cascades in enterprise networks.
APT28 manipulates hotel WLANs through DNS redirection and device code authentication to steal OAuth tokens and bypass MFA—VPN tunneling and encrypted DNS are required.
German and US investigators have shut down the infrastructure of one of the world’s leading phishing kits specifically designed for MFA bypass in Microsoft 365.
HollowGraph uses Microsoft Graph API via the calendar feature for command-and-control communication and data exfiltration within legitimate Microsoft 365 accounts.
A password spray campaign with 81 million login attempts compromised 78 accounts across 64 organizations, revealing widespread configuration weaknesses in Microsoft 365 environments.
ACR Stealer exfiltrates browser credentials and Microsoft 365 content from enterprise environments via ClickFix lures by manipulating users to execute PowerShell commands directly.
O-UNC-066 uses voice phishing combined with deceptively authentic phishing websites and manually controlled PHP panels to steal access from Microsoft 365 customers.