Product
Microsoft 365
- First Reported
- Sep 21, 2026
- Latest Reported
- Sep 29, 2026
Reported Context (3)
- Identity compromise is becoming harder to contain: N0va and CSuite targeted sessions, tokens, and Microsoft 365 access, extending the impact beyond a stolen password. September 2026 Cyber Campaigns Target US and EU With Session Theft, Phishing and Payment Fraud
- ANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations
- For that price the operator supplies lures, domains, hosting, redirects, and support, and relays Microsoft 365 logins in real time in order to capture the authenticated session. The service is reported to be Phishing Kits Steal Valid Sessions, Moving Attacks Beyond MFA
Malware (9)
MITRE ATT&CK (34)
Vendors (10)
Products (12)
Tools (5)
Industries (8)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.