Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
"These stolen tokens enabled attackers to access victim accounts as authenticated users without requiring passwords or bypassing multi-factor authentication (MFA)."
"These stolen tokens enabled attackers to access victim accounts as authenticated users without requiring passwords or bypassing multi-factor authentication (MFA)."
"These stolen tokens enabled attackers to access victim accounts as authenticated users without requiring passwords or bypassing multi-factor authentication (MFA)."
“Variants of the lure’s subject line... substitute the lowercase letter ‘l’ for ‘i’ in words such as ‘Important’ and ‘Signature’ — likely an attempt to dodge spam filters.”
The threat actor sets up a relay to capture valid authentication artifacts right as the victim accepts the MFA push prompt.
Captured session tokens would then be fed into the threat actor's operator console... stolen tokens [were] replayed from the data center hosting ranges.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adversary-in-the-middle phishing kit that uses DocuSign-themed lures and redirect chains to deliver credential/session-token phishing pages. It captures valid Microsoft 365 session tokens and sends them to its control console, allowing attackers to hijack authenticated accounts without needing victims' passwords or defeating MFA directly.
A phishing-as-a-service kit that impersonates Microsoft device-code login flows to capture authenticated Microsoft 365 sessions after victims complete legitimate MFA. Attackers reuse the stolen session tokens to access accounts without needing passwords or additional MFA, then establish persistence by registering rogue Entra ID devices and binding Windows Hello for Business passwordless credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.