Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencecredential-access-methodidentity-authentication-vulnerabilitydefense-evasion-method

Multi-Stage Phishing Campaigns Bypassing MFA to Steal Microsoft 365 Credentials

Updated 3mo agoFirst seen Dec 4, 20253 sources

A wave of sophisticated phishing campaigns is targeting organizations globally to steal Microsoft 365 credentials by bypassing traditional email security gateways and multi-factor authentication (MFA) protections. Attackers are employing advanced techniques such as multi-stage payload delivery using nested PDF attachments, legitimate content delivery networks, and mouse tracking to evade detection. Once victims interact with these emails and enter their credentials on a credential harvesting site, attackers leverage legitimate Microsoft infrastructure to bypass MFA and gain immediate access to the victim’s Microsoft 365 environment. These campaigns are engineered to filter out security analysts and block standard security tools, making detection and response more challenging.

In parallel, threat actors are increasingly using attacker-in-the-middle toolkits like Evilginx and hybrid phishing-as-a-service kits such as Salty2FA and Tycoon2FA to capture both user credentials and session cookies. By stealing session cookies, attackers can impersonate users and maintain access without triggering additional MFA prompts, even after successful authentication. The blending of different phishing kits into hybrid strains is making detection harder, as traditional security rules tuned to individual kits are now being evaded. Security researchers warn that static indicators are no longer sufficient, and behavioral analysis is required to spot these evolving threats.

Share:
Multi-Stage Phishing Campaigns Bypassing MFA to Steal Microsoft 365 Credentials
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 4, 20257mo ago

KnowBe4 reports a multi-stage campaign targeting Microsoft 365 credentials

KnowBe4 published a report describing a multi-stage phishing campaign designed to evade security controls and steal Microsoft 365 credentials. The available reference does not provide further technical or victim details, but indicates a distinct campaign disclosure.

Dec 3, 20257mo ago

Any.Run says hybrid 2FA phishing kit is already evading existing detections

Any.Run said the new hybrid kit was already causing alerts for pure Salty2FA or Tycoon2FA activity to go quiet, indicating active evasion of existing detection rules. The company advised defenders to move away from static IOCs and toward behavioral detection of execution flows, transitions, and fallback routines.

Researchers identify a hybrid Salty2FA–Tycoon2FA phishing kit

Researchers reported that threat actors had combined features of the Salty2FA and Tycoon2FA phishing-as-a-service kits into a harder-to-detect hybrid used to bypass MFA. Analysis showed Salty2FA-like early-stage behavior and Tycoon2FA-like later-stage execution, reducing the effectiveness of signatures tuned to either kit alone.

Attackers increasingly use Evilginx to bypass MFA via session-cookie theft

Threat actors were observed using the Evilginx adversary-in-the-middle phishing toolkit to proxy legitimate login flows, steal credentials and session cookies, and then access accounts without triggering additional MFA prompts. The activity was described as particularly affecting educational institutions and enabling follow-on risks such as data theft, fraud, and unauthorized account changes.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Affected products
1 linked
Aspnet
Organizations
6 linked
Knowbe4Microsoft CorporationShutterstockMalwarebytesCloudflareAny.Run
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Multi-Stage Phishing Campaigns Bypassing MFA to Steal Microsoft 365 Credentials | Mallory