Threat Brief — 2026-09-07 — M365 Credential Theft and Infrastructure Co-option
Two distinct Microsoft 365 attack campaigns dominate today's intelligence: a phishing-as-a-service platform that has already bypassed MFA at 258 organisations, and a vishing operation impersonating IT help desks to steal executive data for extortion. On the infrastructure side, researchers report attackers are increasingly repurposing legitimate internet services for command-and-control traffic, blurring the line between trusted and malicious endpoints. Germany's government is also accelerating a national "cyber dome" programme in response to a hybrid attack in Leipzig.
Top items
- BigBear 2.0 PhaaS bypasses MFA at 258 organisations, stealing 5,000+ M365 credentials. The phishing-as-a-service framework has demonstrated effective MFA evasion across a large number of targets, making it a broadly accessible tool for credential theft against SaaS tenants. The scale — 258 organisations and over 5,000 credentials — indicates this is not a niche tool but a significant commercial threat platform. First reported today. (src: BleepingComputer)
- Fake IT help-desk vishing campaign targets executives for M365 data theft and extortion. Attackers use adversary-in-the-middle techniques and social engineering via phone calls impersonating IT staff, aiming at senior personnel to steal SaaS data and subsequently extort victims. The combination of vishing and AiTM represents a convergence of low-tech social engineering with high-credential-theft capability. First reported today. (src: The Hacker News)
- Attackers co-opt legitimate internet infrastructure for command-and-control of infected machines. Kaspersky reports that threat actors have learned to abuse trusted, legitimate online services and infrastructure to issue commands to compromised computers, making C2 traffic harder to distinguish from normal activity. This trend undermines network-level detection assumptions that rely on reputation-based blocking. (src: SecurityLab)
- Coder registry compromise delivered malicious Terraform modules with credential-stealing payload. Attackers breached Cloudflare infrastructure used by the Coder platform and injected rogue registry servers, causing some developers to pull trojanised Terraform modules containing a stealer. This is a supply-chain compromise targeting developer infrastructure — the blast radius depends on which organisations pulled the tainted modules. First reported 2026-09-03; no new development beyond additional source coverage. (src: Xakep)
- Roskomnadzor reports repelling 1,663 DDoS attacks in August, with near-continuous activity for ~10 days. The scale and sustained nature of the attacks indicates a coordinated campaign against Russian internet infrastructure. While attributed to the regulator's defensive perspective, the volume is notable for threat-landscape awareness. (src: SecurityLab)
- Germany accelerating national "cyber dome" against hybrid threats after Leipzig attack. The planned multi-layered system would integrate defences against drones, hackers, and physical saboteurs. The programme reflects a growing governmental trend toward unified civilian-military cyber and hybrid threat response. (src: SecurityLab)
Themes
Microsoft 365 as the primary SaaS attack surface. Both the BigBear PhaaS campaign and the IT-help-desk vishing operation target M365 credentials, reflecting that O365 tenants remain the highest-value target for both automated phishing and human-operated social engineering. MFA is no longer a sufficient control on its own — AiTM techniques and help-desk social engineering both circumvent it.
Legitimate infrastructure abuse for C2. The Kaspersky finding on attackers using legitimate internet services for command-and-control reinforces a broader pattern: threat actors are increasingly hiding inside trusted infrastructure rather than operating dedicated malicious servers, eroding the effectiveness of reputation-based defences.
Developer tooling as an attack vector. The Coder registry compromise adds to a growing list of supply-chain incidents targeting developer workflows (Terraform modules, npm packages, CI/CD pipelines), where a single tainted artefact can propagate across multiple downstream organisations.
