Itsecurityguru
Knight Office Phishing Kit Targets Microsoft 365 Accounts via Session Hijacking
Article Content
A new phishing kit named 'Knight Office' has been identified, targeting Microsoft 365 accounts by stealing active login sessions instead of passwords. Discovered by Huntress during an investigation of suspicious sign-in activity in August 2026, the kit uses a sophisticated dashboard to manage victims and harvested logins. The attack begins with a fake email styled as a DocuSign request, leading victims through a series of redirects, including legitimate platforms, to a fake Microsoft login page. Once victims enter their login details and approve MFA prompts, their session tokens are captured, allowing attackers to access accounts without needing passwords. Huntress has linked at least nine phishing attacks to this kit in the past two weeks. The phishing kit's design includes a Cloudflare Turnstile for bot-checking and a self-signed TLS certificate, indicating a level of sophistication. The attack method bypasses traditional security measures, making it particularly dangerous for organizations using Microsoft 365.
Key Points: • Knight Office phishing kit captures Microsoft 365 session tokens, bypassing MFA. • Attackers use fake DocuSign emails and redirects to trick victims into revealing session data. • At least nine phishing attacks linked to Knight Office have been reported in two weeks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.