cognitive cybersecurity intelligence

News and Analysis

Search

Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools

Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools

Cybercriminals spent July 2026 proving that trusted business utilities including Microsoft authentication pages, Zoom event invitations, and official government portals can be weaponized against enterprise targets.

Threat intelligence research from ANY.RUN reveals that attackers across the United States, Europe, and Brazil systematically exploited routine corporate workflows to bypass perimeter security controls, harvest credentials, and maintain long-term access to systems.

Hackers Turn Trusted Sites Into Attack Tools

The defining trend across July’s threat landscape was the exploitation of platform legitimacy. Phishing operations systematically routed targets through SharePoint, OneDrive, Microsoft Forms, and legitimate authentication interfaces before delivering malicious payloads.

A phishing-as-a-service (PhaaS) platform known as Kratos deployed document-sharing and DocuSign-style lures to funnel Microsoft 365 users through trusted cloud infrastructure toward credential-harvesting pages.

Because these redirect chains mirrored standard administrative workflows, both automated security gateways and human targets allowed the traffic through.

Kratos phishing attack flow (Image Source: ANY.RUN)

Concurrently, a campaign tracked as Kali365 abused Microsoft’s genuine device-code authentication flow. By directing victims to authentic Microsoft login endpoints and inducing them to enter attacker-generated authorization codes, adversaries obtained OAuth tokens.

These stolen identity tokens granted persistent cloud access to email archives and shared repositories without harvesting account passwords. The campaign recorded over 80 weekly sandbox detections across manufacturing, healthcare, government, and consulting sectors.

Kratos sandbox analysis view (Image Source: ANY.RUN)

Adversaries further expanded delivery mechanisms by abusing legitimate Zoom Event pages, creating fake summits branded around OpenAI, Anthropic, and Meta partner conferences. Tapping the “Continue to register” button redirected targets to device-code phishing interfaces or adversary-in-the-middle (AiTM) proxies.

Zoom event lure templates (Image Source: ANY.RUN)

As detailed in campaign analysis from the ANY.RUN, regional Cyber threat operations similarly weaponized trusted public-sector domains.

In Brazil, the PhantomEnigma campaign compromised over 20 municipal and police web portals (.gov.br) to host malware. Hijacked municipal email accounts dispatched phishing lures that successfully passed SPF, DKIM, and DMARC verification checks.

PhantomEnigma activity timeline (Image Source: ANY.RUN)

Single-device intrusions frequently cascaded into enterprise-wide operational risk. Modular payloads such as DestinyStealer harvested browser credentials, session cookies, Outlook data, VPN profiles, FileZilla logins, and cryptocurrency wallets, exfiltrating data across parallel HTTP and TCP channels.

These specialized infostealer malware strains continue to evade traditional static antivirus detection.

OVERLORD live C2 channel (Image Source: ANY.RUN)

During one active intrusion, researchers monitored an operator deploying OVERLORD RAT via a live command-and-control channel.

Within 45 minutes, the attacker exfiltrated 86 MB of sensitive files, browser sessions, internal messaging logs, and crypto wallet stores.

Meanwhile, variant updates to Banana RAT introduced randomized file structures and encrypted WebSocket communications, while secondary campaigns deployed DARTHVADER Stealer via malicious shortcut files using native Windows utilities, AutoIt, and PowerShell script chains.

Adversaries rely on this resilient command infrastructure to maintain persistent access following initial endpoint execution.

Campaign / ThreatCore Weaponization VectorOperational ImpactKratos PhaaSTrusted cloud redirects & DocuSign luresM365 credential theft & cloud accessKali365OAuth device-code login flow abusePasswordless persistent token harvestingZoom Lure OperationsCounterfeit AI summit event registration pagesAiTM redirection & credential harvestingPhantomEnigmaCompromised .gov.br portals & government mailLegitimate mail auth bypass & RAT deliveryOVERLORD / Banana RATLive C2 channels & encrypted WebSocketsReal-time data exfiltration & persistent access

A critical finding from these July campaigns is that threat actors rotate infrastructure far faster than traditional blacklists can update. Simple password resets often fail to remediate intrusions when active OAuth tokens or session cookies remain valid in attacker hands.

Security teams must move beyond static IOC blocking toward behavior-based telemetry, continuous session monitoring, and campaign-level correlation to identify multi-stage attack chains before lateral movement occurs.
The post Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts