September 2026 Cyber Campaigns Target US and EU With Session Theft, Phishing and Payment Fraud

· Original article ↗

Summary

ANY.RUN describes five September campaigns targeting US and EU users and organizations, involving Microsoft 365 session and token theft, remote-access tools, payment-card and OTP theft, evasive phishing, and multi-stage payload delivery.

Key points

  • CSuite used business-service lures to steal credentials or authenticated Microsoft 365 sessions and, in some cases, install legitimate remote-management tools.
  • N0va used Device Code phishing to obtain Microsoft access and refresh tokens; observed activity also included token exchange and device registration.
  • IronToll impersonated services in more than 12 countries to steal payment-card data and one-time passwords, with a live operator panel and recurring backend patterns.
  • Wazza used routing, anti-bot checks and multiple redirects to conceal its final Device Code phishing page from automated detection.
  • TerminalFix used compromised WordPress sites, encoded payloads, a legitimate Node.js runtime and a signed Microsoft binary; later stages retrieved infrastructure details through a smart contract and public forum profile.
  • The article recommends investigating full browser and execution chains, reviewing sessions and device registrations, checking for unexpected remote-management agents, and correlating identity, endpoint and network evidence.

Article Details

Attack Vectors
  • CSuite uses business-themed phishing lures and counterfeit document pages to capture Microsoft 365 credentials and authenticated sessions or deliver files that install remote-management software.
  • N0va uses device-code phishing through legitimate Microsoft authentication flows to obtain access and refresh tokens; observed activity also includes device registration.
  • IronToll uses cloned service pages to steal payment-card data and one-time passwords, with operators able to request additional details during a victim session.
  • Wazza routes visitors through campaign validation, anti-bot checks, and redirects before showing an Adobe Document Cloud-themed device-code phishing page.
  • TerminalFix targets users through compromised WordPress sites. Its JavaScript represents binary payloads as English-word sequences that a legitimate Node.js runtime decodes; later stages execute through a signed Microsoft binary.
Defensive Notes
  • For CSuite incidents, revoke sessions, review mailboxes, check for unexpected remote-management agents, and investigate affected endpoints.
  • For suspected N0va device-code phishing, review active sessions, device registrations, token activity, and follow-on account access.
  • For IronToll, combine domain blocking with detection of recurring backend paths and other patterns that persist as domains change.
  • For Wazza, inspect the complete browser flow rather than only the initial URL.
  • For TerminalFix, correlate browser activity, script execution, unusual child processes, and outbound connections.

MITRE ATT&CK

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles