Tag: session theft
3 articles

CSuite Phishing Targets US Businesses with Dual Microsoft 365, RMM Attacks
US businesses are in the crosshairs of a cunning phishing attack that combines Microsoft 365 session theft with remote-access tool deployment, allowing hackers to turn a single incident into widespread account compromise, fraud, and persistent system access. This dual-threat attack path puts companies at risk of devastating breaches.

Phishing Service NovaCookies Targets Organizations with 365 Session Theft
Meet NovaCookies, a sneaky phishing service that's stealing Microsoft 365 sessions from hundreds of organizations - and it's available for a low monthly fee of just $320. This subscription-based threat packages real-time session theft, making it a potent and affordable tool for cybercriminals.

REMUS Infostealer Targets Session Theft, Password Managers
Meet REMUS Infostealer, a rapidly evolving threat that's been making waves in the underground scene since February 2026, with its operators boasting a staggering 90% callback rate thanks to top-notch crypting and a dedicated server. This infostealer has quickly become a commercialized and professionalized menace, with a flurry of updates, features, and customer communications flooding the dark web.