Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails
A widespread phishing campaign uses adversary-in-the-middle techniques to compromise Microsoft 365 accounts and target payroll and finance emails.
Category
31 published analyses.
A widespread phishing campaign uses adversary-in-the-middle techniques to compromise Microsoft 365 accounts and target payroll and finance emails.
A suspected Chinese-speaking threat actor has targeted Central Asian government organizations with OctLurk and SilkLurk malware since January 2025, impacting healthcare, research, and government sectors.
The Russian threat group Midnight Blizzard's Storm-2945 sub-cluster has compromised hospitality sign-in portals worldwide since May 2026, delivering malware and stealing traveler credentials.
Amazon attributes multiple supply chain attacks on the Debug and Chalk npm packages to North Korean state-sponsored hackers, exposing risks to open-source software security.
North Korean threat actors have launched a sophisticated macOS malvertising campaign using fake update prompts to deliver crypto-stealing malware as part of the ongoing Contagious Interview operation.
A coordinated cyberattack targeted operational technology at over 30 Minnesota community water systems in late July, causing outages and communication disruptions.
Iranian state-backed group Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers in attacks across the Middle East, Africa, and South Asia, enhancing stealth and covert activity.
Cl0p ransomware affiliates exploit unauthenticated remote code execution vulnerabilities in internet-facing PTC Windchill and FlexPLM systems to conduct data extortion campaigns.
North Korean group BlueNoroff uses a phishing kit impersonating Zoom and Microsoft Teams to profile cryptocurrency wallets and deliver malware via social engineering.
Attackers manipulate DNS settings on hotel and conference center Wi-Fi to redirect users to fraudulent Microsoft 365 login pages, targeting credential theft from business travelers.
CISA warns that Russian state-sponsored group Laundry Bear is exploiting a patched Zimbra zero-click vulnerability combined with phishing to steal emails from enterprise Zimbra Collaboration servers.
Russian intelligence services compromise internet-connected security cameras across Europe and Ukraine to gather military logistics intelligence, as reported by the Netherlands' AIVD and MIVD.
An advanced threat actor exploits the update mechanism of ViPNet private networking software to attack Russian government agencies, illustrating ongoing espionage.
North Korean threat actors linked to the Contagious Interview campaign employ steganography within SVG flag images in fake coding challenges to deliver multi-stage OTTERCOOKIE-aligned malware.
US prosecutors charged three Russian nationals for operating a bulletproof hosting service that enabled ransomware gangs causing over $62 million in damages globally.
Spanish Police arrested four individuals and dismantled a cybercrime network responsible for €140 million in losses through investment fraud and business email compromise attacks.
The EU and UK have imposed joint sanctions on Russian individuals and entities linked to the GRU for orchestrating widespread cyberattacks across Europe, marking the first coordinated cyber sanction package targeting Russian state-sponsored hackers.
Russian state-sponsored hackers from FSB Center 16 are exploiting poorly configured routers in critical infrastructure worldwide, heightening operational risks.
Microsoft Threat Intelligence uncovered ShinyHunters abusing OAuth in SaaS applications through vishing, supply chain attacks, and guest access misconfigurations, exposing new SaaS security risks.
Researchers reveal cyber espionage targeting Pakistani law enforcement by suspected China- and India-aligned groups between 2024 and 2026, compromising police servers with critical data.
Datadog Security Labs warns of campaigns using dormant GitHub accounts and compromised OAuth tokens to scrape corporate GitHub organizations and user data through the GitHub API. Attackers automate scraping with custom or legitimate-sounding user agents to blend in and avoid detection.
A threat actor known as O-UNC-066 is using a phishing kit to exploit Microsoft 365 users via fake Entra passkey enrollment requests, aiming at data extortion. This tactic spans multiple industry sectors and involves voice-based social engineering.
A China-linked threat actor is exploiting a vulnerability in Roundcube webmail servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. This campaign specifically targets academic researchers to gather intelligence.
The Chinese APT actor UAT-7810 is enhancing its ORB network via a new LONGLEASH malware targeting internet-facing networking devices, according to Cisco Talos. This campaign builds on the previously identified LapDogs ORB infrastructure active since mid-2025.
A China-nexus threat group is targeting Indian taxpayers and finance teams with spear-phishing emails impersonating the Income Tax Department to deploy DcRAT, a remote access trojan. This multi-stage campaign aims to steal sensitive data from compromised systems.
An Iran-linked hacker group associated with MOIS has started using a new modular command-and-control framework called Cavern to target Israeli IT providers and government organizations. This activity has been tracked by Check Point Research and highlights evolving state-sponsored cyber threats.
North Korean hackers linked to the Contagious Interview campaign have published 108 malicious packages and browser extensions across multiple platforms as part of their ongoing PolinRider operation. These malicious artifacts are being actively distributed via compromised maintainer accounts on npm, Packagist, Go, and Chrome Web Store.
The China-aligned Mustang Panda group has launched campaigns targeting Indian government networks and hydropower infrastructure using new malware and Zoho WorkDrive as a command channel. Acronis researchers detected active compromises including high-level administrative systems.
The FBI and CISA warn of a phishing campaign by Russian intelligence targeting Signal users to steal backup recovery keys, giving attackers access to historical messages. This represents a significant escalation in targeting secure communications.
Ukraine and the FBI uncovered a Russian intelligence campaign targeting messaging accounts of officials and activists across Ukraine, Europe, and the U.S. The operation involved fake support texts aimed at stealing sensitive credentials.
Microsoft has attributed the recent Mastra AI supply chain attack, compromising over 140 npm packages, to the North Korean group Sapphire Sleet, aka BlueNoroff. This highlights ongoing state-sponsored supply chain risks affecting open source ecosystems.