New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password
Brief
A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it.
The kit, dubbed “Knight Office” by researchers, came to light after Huntress’s Security Operations Centre investigated suspicious sign-in activity on a customer’s Microsoft 365 account in August.
While tracing the source of the intrusion, analysts found the attacker’s own operator console, a slickly built dashboard, complete with a Cloudflare Turnstile bot-check and real-time visitor statistics, used to manage victims and harvested logins from a single screen.
