A Wave of Attacks Built on Everyday Trust
Throughout August, security researchers tracked a cluster of cyberattacks across the United States and Europe that didn't rely on exotic malware or zero-day exploits. Instead, attackers turned the tools businesses use every single day, Microsoft 365 logins, remote monitoring and management (RMM) software, and routine business documents, into pathways for compromise.
This is what makes the campaign notable. Rather than breaking through firewalls or exploiting unpatched software, the attackers leaned on the fact that employees trust the platforms they log into each morning and the vendors who remotely manage their IT systems. That trust, once abused, becomes one of the most effective attack surfaces available.
How Microsoft 365 Session Hijacking Works
At the center of this campaign is a technique known as session hijacking. Rather than stealing a username and password outright, attackers intercept or steal the authentication token, or "session cookie," that Microsoft 365 generates after a user successfully logs in and completes multi-factor authentication. Because that token proves the session is already verified, an attacker who obtains it can effectively become the logged-in user without ever needing the original password again.
This matters because multi-factor authentication, long considered a strong defense against credential theft, doesn't stop an attacker who has already captured a valid session. The login event has already happened legitimately from the victim's perspective. Once inside, attackers can access email, shared files, calendars, and internal communications tied to that Microsoft 365 account, often without triggering the kinds of alerts that a failed login attempt or new-device notification would raise.
Remote Management Tools and Business Documents as Entry Points
The same August campaign also leaned on remote monitoring and management (RMM) software, the kind of tool IT departments and managed service providers use to install updates, troubleshoot issues, and maintain systems remotely. When attackers gain access to these tools, either by hijacking credentials or exploiting weak configurations, they inherit the same level of trusted access that a legitimate IT administrator would have. That can mean the ability to push files, run commands, or move across an entire network of connected devices with minimal friction.
Routine business documents played a role as well. Files that look like invoices, contracts, or internal memos are still one of the most reliable ways to get an employee to click a link or open an attachment, precisely because they don't look suspicious. Combined with session hijacking and RMM abuse, a single convincing document can be the first domino in a much larger intrusion.
This pattern echoes a broader trend in cybercrime enforcement, where authorities have increasingly targeted the infrastructure and individuals behind large-scale attacks rather than just individual incidents. Sanctions actions like the one against the Trickbot ransomware operation's administrator show how governments are trying to disrupt the ecosystem that makes these campaigns profitable, even as new variations on old techniques keep emerging.
What This Means For You
For most individuals, this campaign is a reminder that strong passwords and even multi-factor authentication aren't a complete safety net if a session token can be stolen through phishing or malware. For employees at small and mid-size businesses in particular, where IT resources may be stretched thin and RMM tools are commonly used by outside vendors, the risk of this kind of abuse is real.
If you use Microsoft 365 for work, pay attention to unexpected prompts to re-authenticate, unfamiliar login locations flagged in security notifications, or requests to approve a device you don't recognize. If your organization relies on a third-party IT provider using remote management software, it's worth asking how that access is secured and monitored. And as always, treat unexpected documents, especially ones urging quick action, with healthy skepticism before opening them.
Actionable Takeaways
- Review Microsoft 365 sign-in activity logs periodically and report any unfamiliar sessions or locations immediately.
- Ask your IT provider or internal team how RMM software access is authenticated and whether session monitoring is in place.
- Avoid opening unexpected business documents, invoices, or attachments without verifying the sender through a separate channel.
- Consider enabling conditional access policies and shorter session timeout windows for cloud accounts where possible.
- Stay informed about how attackers are adapting to bypass multi-factor authentication, since Microsoft 365 session hijacking shows that MFA alone isn't a guaranteed defense.
The August wave of attacks didn't require sophisticated new malware to succeed. It succeeded by exploiting the everyday trust businesses place in familiar logins, familiar vendors, and familiar file types. Staying alert to that reality is one of the simplest and most effective defenses available.




