August 2026 Cyberattacks Targeted U.S. and European Businesses Through Session Theft and Remote Access

· Original article ↗

Summary

ANY.RUN's August roundup describes campaigns abusing legitimate remote-management tools, Microsoft 365 sessions, hiring processes and business-themed files to gain access, steal credentials and deploy remote-control malware against U.S. and European organizations.

Key points

  • A phishing campaign observed in 46 countries used business-themed documents to trick victims into installing legitimate RMM tools; 45% of observed activity was associated with the United States.
  • An investigation into suspected Famous Chollima operatives found forged or stolen identities and remote-access tools used in a fake hiring process, exposing how false identities could gain legitimate access to internal systems and intellectual property.
  • Mirage2FA reportedly targeted more than 4,000 U.S. victims, stealing credentials, MFA codes and session cookies to hijack Microsoft 365 sessions.
  • SnakeBiteAgent, a .NET remote-access trojan delivered in a business-themed ZIP file, can steal credentials, log keystrokes, capture webcam and microphone activity, and install additional remote-access tools.
  • The 3DBlast phishing kit impersonated Microsoft, Office 365 and Google login flows and could switch techniques, including AiTM and OAuth/device-code phishing.
  • The article recommends revoking compromised sessions and tokens, investigating activity under affected identities, using phishing-resistant MFA, and monitoring for unexpected RMM installations and remote-access activity.

Article Details

Event Type
Reporting on phishing, session hijacking, remote-access malware, abuse of legitimate remote-management software, and suspected insider infiltration observed in August 2026.
Impact
ANY.RUN reported a remote-management phishing operation spanning 46 countries, with 45% of observed activity associated with the United States. Mirage2FA affected over 4,000 victims in the United States, with session theft reported as the most common compromise outcome. Reported exposure included corporate accounts, credentials, email, cloud files, and internal documents. SnakeBiteAgent could provide full remote control, credential theft, and persistent surveillance. An investigation involving suspected Famous Chollima operatives demonstrated how fraudulent hiring identities could obtain legitimate access to source code, internal systems, and intellectual property.

MITRE ATT&CK

Threat Actors

Malware

Vendors

Products

AnyDeskIts capabilities include credential theft, keylogging, hidden desktop access, webcam and microphone capture, and silent installation of AnyDesk and MeshCentral for additional remote access.ConnectWiseThe campaign abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian to establish hands-on remote access.GoTo ResolveThe campaign abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian to establish hands-on remote access.ITarianThe campaign abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian to establish hands-on remote access.LogMeIn RescueThe campaign abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian to establish hands-on remote access.MeshCentralIts capabilities include credential theft, keylogging, hidden desktop access, webcam and microphone capture, and silent installation of AnyDesk and MeshCentral for additional remote access.Microsoft 365Across the US and Europe, attackers abused Microsoft 365 sessions, legitimate remote-management tools, business-themed files, and even hiring processes to reach corporate systems.Office 365A newly observed phishing kit, 3DBlast, targeted users in the United States while impersonating Microsoft 365, Office 365, and Google.ScreenConnectThe campaign abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian to establish hands-on remote access.

Tools

Countries

Industries

Related Articles