Knight Office Phishing Kit Targets Microsoft 365 Accounts via Session Hijacking

Knight Office Phishing Kit Targets Microsoft 365 Accounts via Session Hijacking

First seen 2 Sep 2026, 20:13 UTC Huntressattack.mitre.orgItsecurityguru 68.2

Article Content

Browse articles
ThreatCluster

A new phishing kit named 'Knight Office' has been identified, targeting Microsoft 365 accounts by stealing active login sessions instead of passwords. Discovered by Huntress during an investigation of suspicious sign-in activity in August 2026, the kit uses a sophisticated dashboard to manage victims and harvested logins. The attack begins with a fake email styled as a DocuSign request, leading victims through a series of redirects, including legitimate platforms, to a fake Microsoft login page. Once victims enter their login details and approve MFA prompts, their session tokens are captured, allowing attackers to access accounts without needing passwords. Huntress has linked at least nine phishing attacks to this kit in the past two weeks. The phishing kit's design includes a Cloudflare Turnstile for bot-checking and a self-signed TLS certificate, indicating a level of sophistication. The attack method bypasses traditional security measures, making it particularly dangerous for organizations using Microsoft 365.

Key Points: • Knight Office phishing kit captures Microsoft 365 session tokens, bypassing MFA. • Attackers use fake DocuSign emails and redirects to trick victims into revealing session data. • At least nine phishing attacks linked to Knight Office have been reported in two weeks.

Timeline

2026-08-01
Investigation of suspicious sign-ins begins
Huntress starts investigating unusual sign-in activity on a Microsoft 365 account, leading to the discovery of the Knight Office kit.
Huntress
2026-09-02
Knight Office phishing kit publicly reported
Huntress publishes findings on the Knight Office kit, detailing its operation and attack methods.
Huntress
2026-09-02
IT Security Guru reports on Knight Office
ITsecurityguru confirms Huntress's findings, emphasizing the kit's ability to bypass MFA and capture session tokens.
Itsecurityguru