Zum Hauptinhalt springen
Join Us at our First In-Person User Conference.Register for our Dallas event today

Exposing VENOM: C-Suite Credential Theft Campaign Weaponizes Live Microsoft Authentication to Establish Persistent Access

A credential theft campaign targets C-suite executives, intercepting live Microsoft sign-ins and abusing OAuth protocols to establish persistent access.

Wichtige Erkenntnisse

C-suite executives including CEOs and CFOs across 20+ industries are targeted by name, not randomly, in this credential theft campaign.

Attackers exploit legitimate Microsoft authentication flows to relay credentials or capture OAuth tokens, turning one sign-in into persistent access.

QR codes and layered filtering are used to bypass email scanners, URL analysis tools, and security logs before the payload reaches the target.

VENOM is a previously undocumented phishing-as-a-service platform discovered during investigation that enables these attack techniques to scale.

The attack is a coordinated chain where each stage is engineered to protect the next, not a collection of isolated tactics.

Den vollständigen Bericht herunterladen

Teilen Sie uns mit, wohin wir ihn senden sollen — Sie erhalten sofortigen Zugriff.

Überspringen

CEOs, CFOs, and senior officers across 20+ industries are being targeted by name in a credential theft campaign engineered for persistent access that can survive standard remediation.

Attackers impersonate SharePoint notifications to initiate the attack, using QR codes and layered filtering to evade scanners and security tools before reaching the target. From there, the campaign operates within legitimate Microsoft authentication flows, relaying credentials or capturing OAuth tokens to convert a single sign-in into persistent access.

This is not a single tactic, but a coordinated attack chain where each stage is designed to protect the next. In investigating the campaign, Abnormal Threat Intelligence also identified VENOM, a previously undocumented phishing-as-a-service platform supporting the operation and enabling these techniques to scale.

Exposing VENOM outlines how the attack works and the actions security leaders can take to defend against it.

Download the Threat Intelligence Report to:

  • Understand how attackers turn live Microsoft sign-ins into persistent access

  • See the evasion techniques that defeat scanners, URL tools, and logs

  • Discover VENOM, the undocumented PhaaS platform found during investigation

  • Learn the strategic defenses CISOs should implement immediately

Fill out the form to get your copy today.

ISC2-CPE-Punkte sammeln (1 Punkt)

Diese Ressource ist für ISC2-CPE-Punkte qualifiziert. Reichen Sie das Punkte-Formular ein, um Ihre Fortbildungspunkte zu beantragen.

Abnormal in Aktion erleben

Erfahren Sie, wie verhaltensbasierte KI Angriffe erkennt, die klassische Abwehrmaßnahmen übersehen.