<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password-dzt96pdo3" -->

---
title: New ‘Knight Office’ Phishing Kit Steals Microsoft 365...
description: A phishing-as-a-service kit dubbed &#x27;Knight Office&#x27; is hijacking Microsoft 365 accounts by stealing active login sessions instead of passwords, letting...
canonical: https://daily.dev/posts/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password-dzt96pdo3
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password | daily.dev
og:description: A phishing-as-a-service kit dubbed &#x27;Knight Office&#x27; is hijacking Microsoft 365 accounts by stealing active login sessions instead of passwords, letting...
og:url: https://daily.dev/posts/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password-dzt96pdo3
og:image: https://api.daily.dev/og/posts/dzT96pdo3.png
og:image:alt: New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password

**[IT Security Guru](https://daily.dev/sources/itsecurityguru)** · 4 min read · 0 upvotes · 0 comments

## Summary

A phishing-as-a-service kit dubbed 'Knight Office' is hijacking Microsoft 365 accounts by stealing active login sessions instead of passwords, letting attackers bypass MFA entirely. Discovered by Huntress after investigating suspicious sign-in activity, the kit uses self-spoofed DocuSign-style emails and multi-hop redirects through legitimate services like Monday.com and a compromised Joomla site to reach a fake Microsoft device-login page. Once victims complete a real login and MFA approval, their live session token is intercepted and reused from data-center infrastructure, evading password-based detection. Attackers have also been registering rogue devices and binding Windows Hello for Business credentials to compromised accounts as a persistence backdoor. Huntress linked the operator console to at least nine confirmed attacks in two weeks and over 700 similar reported emails since April, and published IOCs including a control panel IP, hosting domain, and dozens of lookalike .vu phishing domains.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.itsecurityguru.org/2026/09/02/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password>

## Questions this post answers

### How does the Knight Office phishing kit bypass Microsoft 365 MFA without stealing a password?

It steals the victim's active login session token rather than their credentials. Victims are lured through a fake DocuSign-style email to a spoofed Microsoft device-login page; once they complete a real login and approve the MFA prompt, the attacker's infrastructure intercepts the live session, making it instantly reusable without needing the password or a separate MFA approval.

_Security teams tracking session-hijacking phishing techniques like this follow the latest research on daily.dev._

### Why didn't password-spray or failed-login alerts detect the Knight Office phishing campaign?

Because no password was ever entered incorrectly, standard password-based detection never triggered; the attack captured a valid session token after a genuine login and MFA approval, so it appeared as normal authentication activity. Huntress recommends monitoring post-MFA authentication events from unfamiliar devices instead of relying on failed-login signals.

_Teams hardening detection against AiTM phishing can follow ongoing analysis like this on daily.dev._

### How are attackers maintaining persistent access after a Microsoft 365 account compromise via session token theft?

They register a rogue, attacker-controlled device against the victim's Microsoft Entra ID tenant and bind a Windows Hello for Business passwordless credential to the compromised account. This creates a backdoor allowing continued access even after the original stolen session token is revoked, turning a passwordless security feature into a persistence mechanism.

_Admins reviewing Entra ID device registrations for backdoors like this track defensive guidance on daily.dev._

## Similar posts on daily.dev

- [New phishing kits target Microsoft 365 accounts, evade MFA](https://daily.dev/posts/new-phishing-kits-target-microsoft-365-accounts-evade-mfa-okjl7d0zb) · BleepingComputer · 1 upvotes · 0 comments

---

Tags: [#cloud](https://daily.dev/tags/cloud), [#microsoft](https://daily.dev/tags/microsoft), [#authentication](https://daily.dev/tags/authentication), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password-dzt96pdo3)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password","url":"https://daily.dev/posts/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password-dzt96pdo3","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password-dzt96pdo3"},"datePublished":"2026-09-02T20:41:46.752Z","dateModified":"2026-09-08T13:26:21.994Z","description":"A phishing-as-a-service kit dubbed 'Knight Office' is hijacking Microsoft 365 accounts by stealing active login sessions instead of passwords, letting...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0a094c6c0f74ed6c69349280b6b449a3?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0a094c6c0f74ed6c69349280b6b449a3?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"IT Security Guru","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"IT Security Guru","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/ae9fe7d07c814192b35f86ad698fb374","url":"https://daily.dev/sources/itsecurityguru"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password-dzt96pdo3","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cloud,microsoft,authentication,phishing","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"IT Security Guru","item":"https://daily.dev/sources/itsecurityguru"},{"@type":"ListItem","position":3,"name":"New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password-dzt96pdo3#faq","mainEntity":[{"@type":"Question","name":"How does the Knight Office phishing kit bypass Microsoft 365 MFA without stealing a password?","acceptedAnswer":{"@type":"Answer","text":"It steals the victim's active login session token rather than their credentials. Victims are lured through a fake DocuSign-style email to a spoofed Microsoft device-login page; once they complete a real login and approve the MFA prompt, the attacker's infrastructure intercepts the live session, making it instantly reusable without needing the password or a separate MFA approval. Security teams tracking session-hijacking phishing techniques like this follow the latest research on daily.dev."}},{"@type":"Question","name":"Why didn't password-spray or failed-login alerts detect the Knight Office phishing campaign?","acceptedAnswer":{"@type":"Answer","text":"Because no password was ever entered incorrectly, standard password-based detection never triggered; the attack captured a valid session token after a genuine login and MFA approval, so it appeared as normal authentication activity. Huntress recommends monitoring post-MFA authentication events from unfamiliar devices instead of relying on failed-login signals. Teams hardening detection against AiTM phishing can follow ongoing analysis like this on daily.dev."}},{"@type":"Question","name":"How are attackers maintaining persistent access after a Microsoft 365 account compromise via session token theft?","acceptedAnswer":{"@type":"Answer","text":"They register a rogue, attacker-controlled device against the victim's Microsoft Entra ID tenant and bind a Windows Hello for Business passwordless credential to the compromised account. This creates a backdoor allowing continued access even after the original stolen session token is revoked, turning a passwordless security feature into a persistence mechanism. Admins reviewing Entra ID device registrations for backdoors like this track defensive guidance on daily.dev."}}]}
```

