← Back to feed
PhishingEmerging1 sourceSep 2, 2026 · 12:59via IT Security Guru

New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password

Brief

A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it.

The kit, dubbed “Knight Office” by researchers, came to light after Huntress’s Security Operations Centre investigated suspicious sign-in activity on a customer’s Microsoft 365 account in August.

While tracing the source of the intrusion, analysts found the attacker’s own operator console, a slickly built dashboard, complete with a Cloudflare Turnstile bot-check and real-time visitor statistics, used to manage victims and harvested logins from a single screen.

Read more on IT Security Guru