← Back to feed
Threat Actors & CampaignsEmerging1 sourceMar 23, 2026 · 21:00via Huntress Blog

Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure

Brief

Railway PaaS is being weaponized as a clean token replay engine in an active AiTM and device code phishing campaign impacting 268+ M365 organizations and 100+ MSPs.

Read more on Huntress Blog