Microsoft 365 login theft campaign abusing office.com redirects
Campaign
Summary
Hide ▲
Show ▼
A recent phishing campaign is abusing office.com and ADFS redirects to steal Microsoft 365 logins, increasing the chance that trusted Microsoft infrastructure will bypass URL-based detection and MFA. The operation began with a malicious sponsored Google result for "Office 265" and sent targets through outlook.office.com to a phishing page. It also used conditional loading so only selected victims saw the credential-harvesting site.
Related Happenings
Tycoon 2FA internal-domain phishing campaign abusing email routing
Campaign
H score39
First: 07.01.2026 11:42
Last: 07.01.2026 11:42
Sources 1
About this happening:
An active Tycoon 2FA phishing campaign is abusing misconfigured email routing and weak domain spoofing protections to make messages look like they came from trusted in...
Tycoon 2FA internal-domain phishing campaign abusing email routing
CampaignAbout this happening: An active Tycoon 2FA phishing campaign is abusing misconfigured email routing and weak domain spoofing protections to make messages look like they came from trusted in...
Microsoft 365 OAuth device code phishing campaign
Campaign
H score32
First: 19.12.2025 19:19
Last: 19.12.2025 19:19
Sources 1
About this happening:
Microsoft 365 device-code phishing activity in June 2025 into July 2026 used the legitimate Microsoft device login flow and Evilginx-based tooling to capture token...
Microsoft 365 OAuth device code phishing campaign
CampaignAbout this happening: Microsoft 365 device-code phishing activity in June 2025 into July 2026 used the legitimate Microsoft device login flow and Evilginx-based tooling to capture token...
Latest development: 13.07.2026 18:30
Lexfo reconstructed a deleted configuration file and internal bot timestamps showing saroula01's OAuth Device Code Flow framework had been active since June 2025, with 218 confirmed victims across 12 countries and captured tokens refreshed up to 25 times to preserve access.
RaccoonO365 Microsoft 365 credential-harvesting phishing campaign
Campaign
H score49
First: 19.12.2025 12:26
Last: 19.12.2025 12:26
Sources 1
About this happening:
The RaccoonO365 phishing operation drove repeated Microsoft 365 account compromises and created follow-on risk of business email compromise across corporate, financi...
RaccoonO365 Microsoft 365 credential-harvesting phishing campaign
CampaignAbout this happening: The RaccoonO365 phishing operation drove repeated Microsoft 365 account compromises and created follow-on risk of business email compromise across corporate, financi...
Latest development: 19.12.2025 21:05
Nigeria Police Force National Cybercrime Centre (NPF–NCCC) arrested three suspects linked to Raccoon0365, including Okitipi Samuel, also known as RaccoonO365 and Moses Felix, whom police believe developed the phishing platform used for Microsoft 365 credential theft. The operation used Microsoft intelligence shared via the FBI, and forensic analysis linked recovered laptops, mobile devices, and other digital equipment to the fraudulent scheme.
ToddyCat Outlook email and Microsoft 365 token theft activity
Malware Activity
H score29
First: 25.11.2025 13:36
Last: 25.11.2025 13:36
Sources 1
About this happening:
ToddyCat expanded its email-theft tradecraft by using TCSectorCopy to copy Outlook OST files and harvest correspondence from target companies, increasing the risk that...
ToddyCat Outlook email and Microsoft 365 token theft activity
Malware ActivityAbout this happening: ToddyCat expanded its email-theft tradecraft by using TCSectorCopy to copy Outlook OST files and harvest correspondence from target companies, increasing the risk that...
Sneaky2FA Microsoft 365 BitB phishing campaign
Campaign
H score33
First: 19.11.2025 23:59
Last: 19.11.2025 23:59
Sources 1
About this happening:
The Sneaky2FA phishing operation has added browser-in-the-browser (BitB) lures on top of its existing AitM flow, making credential and session theft more convincing ag...
Sneaky2FA Microsoft 365 BitB phishing campaign
CampaignAbout this happening: The Sneaky2FA phishing operation has added browser-in-the-browser (BitB) lures on top of its existing AitM flow, making credential and session theft more convincing ag...
Timeline
-
20.08.2025 18:33 1 articles · 10mo ago
Push Security discloses Microsoft 365 phishing chain using office.com and ADFS redirects
Initial DisclosurePush Security disclosed a recent campaign that targeted several customers and redirected employees from a legitimate outlook.office.com link into a phishing page stealing Microsoft 365 logins. The chain began with a malicious sponsored Google result for "Office 265", passed through Microsoft office.com to bluegraintours[.]com, and used a custom Microsoft tenant with Active Directory Federation Services (ADFS) plus conditional loading to make the credential-harvesting page appear trusted and to bypass URL-based detection and multi-factor authentication.
Show sources
- Hackers steal Microsoft logins using legitimate ADFS redirects — www.bleepingcomputer.com — 20.08.2025 18:33