Tag

Mfa Bypass

All articles tagged with #mfa bypass

Device Code Phishing Surges in 2026, Defeating MFA Across Platforms
security2 days ago

Device Code Phishing Surges in 2026, Defeating MFA Across Platforms

Device code phishing, using OAuth 2.0 device flows, has become an industrial-scale threat in 2026, enabling token theft that defeats MFA across providers via a thriving phishing-as-a-service ecosystem with 25+ kits. Attackers shift from authentication to authorization abuse, driven by AI-assisted kit development, and detection must occur at the browser during the device-code approval, since network defenses can’t block these attacks.

Global crackdown shuts down Kratos phishing kit that hijacked Microsoft 365 sessions
technology12 days ago

Global crackdown shuts down Kratos phishing kit that hijacked Microsoft 365 sessions

German and U.S. authorities dismantled Kratos, a widely used phishing kit that stole Microsoft 365 session cookies to bypass MFA, shutting down 200+ servers and affecting about 1,800 paying customers who ran some 15,000 campaigns a month. Victims number in the hundreds of thousands across 30+ countries; operators earned over €300,000 since 2024. The kit offered credential-only mode or a real-time adversary-in-the-middle reverse-proxy mode. Microsoft Threat Intelligence links it to SneakyLog; campaigns have used tax-themed W-2 emails with QR codes to lure targets. Stolen credentials can be sold or used to move laterally in Microsoft 365. Mitigations include password resets with MFA checks for credential-only hits, revoking sessions for session-stealing hits, and adopting phishing-resistant sign-ins for high-value accounts. Indicators include login-page assets barr.svg and lg.svg and endpoints like next.php or save.php. The takedown halts Kratos campaigns for now, but the kit and its customers persist elsewhere.

Phishers roll out two new kits to target Microsoft 365, sidestep MFA
technology19 days ago

Phishers roll out two new kits to target Microsoft 365, sidestep MFA

Two new phishing toolkits, Jalisco and OmegaLord, target Microsoft 365 accounts and bypass MFA: Jalisco uses OAuth device-code phishing to trick victims into authorizing attacker-controlled devices and can auto-generate fresh device codes to defeat the 15-minute window, while OmegaLord masquerades as a PDF reader to steal credentials and phone numbers to aid MFA interception. Attacks can lead to rapid data exfiltration from SharePoint and other SaaS apps, sometimes within minutes, prompting researchers to urge tighter controls: reduce Entra ID device-registration limits from 50 to 1-2, block device-code authentication via Entra Conditional Access, restrict OAuth Device Authorization grants in Okta, and audit/remove unnecessary app registrations.

FBI Warns Kali365 PhaaS Bypasses MFA on Microsoft 365
cybersecurity2 months ago

FBI Warns Kali365 PhaaS Bypasses MFA on Microsoft 365

The FBI issued a PSA about Kali365, a phishing‑as‑a‑service that exploits Microsoft’s OAuth device-code flow to hijack Entra and Microsoft 365 accounts, stealing session tokens and bypassing MFA. Kali365, distributed via Telegram, provides AI‑generated phishing lures, automated campaigns, and real‑time dashboards, with two attack modes: device‑code phishing and a Cookie Link adversary‑in‑the‑middle. Arctic Wolf observed global campaigns targeting Microsoft 365 environments, including creating malicious inbox rules and registering new devices. The FBI urges blocking device‑code authentication with Conditional Access, auditing usage, reporting incidents to IC3, and preserving phishing emails and suspicious activity. Device-code phishing has surged in 2026, with other PhaaS tools like EvilTokens and Tycoon2FA using similar methods.

Consent Phishing Turns OAuth Grants into Long-Lived Access Tokens
technology2 months ago

Consent Phishing Turns OAuth Grants into Long-Lived Access Tokens

Security researchers warn that phishing via OAuth consent screens can bypass MFA by stealing refresh tokens, enabling attackers to access mail, drive, and calendars across Microsoft 365 tenants. EvilTokens reportedly compromised 340+ orgs in five countries by tricking users into approving scopes, leaving tokens valid for weeks or months unless explicitly revoked. The risk arises because consent flows sit outside traditional authentication controls and can bridge multiple apps—a 'toxic combination.' Mitigations include continuous OAuth/app inventory, monitoring grant age and re-consent, cross-application identity tracking, conditional access on consent events, and token-level revocation; platforms like Reco claim to map these grants to an identity graph for proactive detection and revocation.

SonicWall Faces Multiple Security Breaches and Urges Customer Action
cybersecurity10 months ago

SonicWall Faces Multiple Security Breaches and Urges Customer Action

Akira ransomware attacks on SonicWall VPNs continue despite MFA, exploiting stolen OTP seeds and a known access control flaw (CVE-2024-40766). Threat actors use stolen credentials and advanced techniques like BYOVD to bypass security, emphasizing the need for immediate credential resets and firmware updates to mitigate ongoing risks.