Skip to Main Content
Faint pattern of 1s and 0s on top of hexagons

Even cyber security firms get targeted: inside a sophisticated M365 phishing attempt

Faint pattern of locks, 1s and 0s on top of hexagons

In the constantly evolving landscape of cyber security, no organisation is immune to being targeted, even here at Mondas we were reminded of how attackers are continually refining their methods to breach even well fortified perimeters.

We recently intercepted a sophisticated phishing and credential harvesting attempt aimed directly at our internal team. By dissecting this real-world attempt, we hope to shed light on the advanced techniques threat actors are deploying today and highlight why a robust defence requires a seamless blend of human vigilance and best-in-class technology.

The lure: a plausible inbound lead

The attack began where many legitimate business transactions do, our website’s inbound enquiry form. A prospect reached out expressing interest in our services and the details appeared genuine, tailored to what we do, and raised no immediate red flags.

But, upon follow-up from our sales team, the prospect replied saying they couldn’t jump on a call but they offered to send over a technical requirements document for our review and response.

This is a common scenario in the B2B world. Legitimate clients frequently share RFQs or technical specifications via file-sharing platforms. If we were to write a hard-and-fast business rule blocking all such interactions, we would inevitably block genuine business.

The human firewall: vigilance in action

When the files arrived, they were hosted on a third-party transfer site (SwissTransfer). At this point, our sales representative became suspicious.

At Mondas, we take the view that security is as much a human issue as it is a technological one. We conduct regular internal phishing simulation tests and awareness training, using tools like KnowBe4. This continuous education fosters a healthy level of cynicism and vigilance within our team. Rather than blindly downloading the document to secure a potential deal, our representative paused and escalated the interaction to our 24/7 Security Operations Centre for triage.

The SOC investigation: uncovering an OAuth 2.0 trap

Our SOC team quickly isolated the communication and began digging into the underlying architecture of the provided link. What they uncovered was a masterclass in modern, evasive cyber attacks designed specifically to harvest Microsoft 365 credentials.

Here is a brief look at the sophisticated mechanics the attackers employed:

Deep Browser Fingerprinting

The malicious infrastructure didn’t just serve a payload; it actively probed the visitor. It checked for over 30 automation variables and analysed behavioural tracking (like mouse velocity and scroll frequency) to ensure a real human was interacting with the page, dynamically blocking bots and security researchers.

Fake CAPTCHAs & Evasion Tactics

The initial download was an SVG file disguised as a security verification page. It rendered a fake CAPTCHA box, but embedded within was obfuscated JavaScript designed to hijack the user’s session regardless of where they clicked.

OAuth 2.0 Device Code Phishing

Perhaps the most alarming aspect of this attack was its endgame. Instead of a traditional fake login form, the attackers utilised an OAuth 2.0 Device Code Flow. By proxying requests to legitimate Microsoft endpoints, they generated a device authorisation code. Had a user entered this code, Microsoft would have issued an OAuth Access Token directly to the attacker, effectively bypassing Multi-Factor Authentication (MFA) and FIDO2 keys.

Crucially, the threat doesn’t end at the initial point of access. Device code phishing grants not just a normal access token but a secondary refresh access token, which grants the threat actor persistence across password changes. This means that simply resetting a compromised user’s password is no longer sufficient to evict the attacker from your environment once the token has been successfully harvested.

For further reading on how these systemic threats operate at a macro level and how to secure cloud environments, we highly recommend reviewing the 🔗National Cyber Security Centre (NCSC) guidance on defending against phishing attacks as well as familiarising yourself with 🔗Microsoft’s documentation on Device Code flow.

The failsafe: Next-Gen EDR

The human element was our first line of defence in this incident, and it worked flawlessly. But, we always operate under the assumption that a human might click the link.

Had the sales representative proceeded, our technology stack would have intervened. As CrowdStrike Premium Partners, we deploy their market-leading, next-generation Endpoint Detection and Response (EDR) tools across our entire estate. The advanced AI-driven behavioural analytics within our EDR would have flagged the suspicious execution and isolated the threat before any credential breach could occur.

The growing threat landscape

What makes this incident particularly relevant is that it’s not an isolated event. We recently dealt with an attempted breach for one of our own clients using this exact OAuth 2.0 Device Code method. As AI makes it easier for threat actors to craft highly convincing, grammatically perfect, and contextually accurate lures, the volume and sophistication of these attacks will only grow.

Protecting your organisation requires more than just blocking suspicious emails. It requires comprehensive triage capabilities, rapid detection, and failsafe protection mechanisms.

The good news is that enterprise-grade security tools are more attainable than ever for businesses of all sizes. By combining regular staff training with best-in-class technology, you can create a resilient security posture capable of withstanding the modern threat landscape.

Has this article raised concerns about your own security posture? If you are struggling with the issues outlined in this article or want to ensure your team and tech are prepared for advanced phishing threats, contact us today. Mondas specialises in protecting businesses from these exact scenarios.

Article First Published: Thursday, August 6, 2026