The Knight Office phishing-as-a-service kit is targeting Microsoft 365 and Google Workspace users with adversary-in-the-middle phishing that captures authenticated session tokens rather than passwords. The campaign sends self-spoofed DocuSign lures through redirect chains involving Monday.com tracking links and compromised Joomla sites, then presents counterfeit Microsoft device-login, SharePoint, or Teams pages. Victims who complete legitimate MFA approval can have their active sessions replayed by attackers to access their accounts.
Following account takeover, operators register rogue devices in Microsoft Entra ID and bind Windows Hello for Business passwordless key credentials to retain access. Huntress identified at least nine token-replay logins over two weeks and more than 700 matching lure emails reported since April, indicating a sustained campaign. Organizations should investigate unusual Entra device registrations and WHfB credential additions, revoke active sessions for suspected accounts, and block the identified phishing redirect infrastructure and lures.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Following session-token theft, the attackers replayed valid Microsoft 365 tokens and enrolled an unauthorized host in the victim's Microsoft Entra ID tenant. They then bound a Windows Hello for Business key credential to the compromised account, enabling passwordless persistence even if the stolen session was revoked.
On August 18, 2026, Huntress investigated an adversary-in-the-middle phishing attack against an organization and identified the operator console for the Knight Office phishing kit. The campaign used self-spoofed DocuSign lures, Monday.com redirects, compromised Joomla sites, and counterfeit Microsoft SharePoint or Teams pages to capture Microsoft 365 sessions after MFA approval.
Huntress identified at least 700 reported emails using Knight Office-related DocuSign, voicemail, document-sharing, and signature-notification lure templates since April 2026. The emails used self-spoofing and some variants substituted lowercase “l” for “i” to evade filtering.
Researchers published 25 Knight Office-associated malicious domains, infrastructure IPs 154.127.53.78 and 104.37.188.94, a Cloudflare Turnstile sitekey, a phishing-email subject pattern, and a Dsreg user-agent indicator. The report also supplied detection logic for connections involving the listed domains and IP addresses.
Huntress linked at least nine token-replay identity logins in its customer base to Knight Office infrastructure during the two weeks preceding its report. Stolen tokens were replayed from the phishing-control-panel IP address 104.37.188[.]94 and Tencent Cloud address ranges.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 28 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourceitsecurityguru.org
Open sourcehuntress.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.