FBI warns of password-less Microsoft 365 phishing: MFA bypassed
The FBI has sounded the alarm: fraudsters are abusing legitimate Microsoft 365 services to gain access to accounts without a password. Multiple waves of attacks are threatening organisations worldwide.

Phishing attack waves against Microsoft 365, npm and FIFA fans uncovered
Security researchers and US federal authorities have uncovered multiple sophisticated phishing campaigns targeting Windows users, developers and cloud platforms. boerse-express.com reports on an escalating threat landscape ranging from file-less malware to artificial intelligence tool imitations to the abuse of legitimate authentication processes.
Counterfeit AI tools lure developers
Security firms Howler Cell and HEAL Security report on a campaign that attracts developers through imitated AI programming tools such as Claude Code and OpenAI Codex. The attackers rely on SEO poisoning and manipulated Google pages to trick victims into downloading infected installation files.
The technique employed is called ClickFix: victims are instructed to enter a command via the Windows Run dialog (Win+R). This triggers a multi-stage PowerShell sequence that uses steganography – malicious payloads are hidden in image files. Researchers identified a 6.7 MB polyglot file that functions as both an MP3 and an HTA file, delivering a .NET-based infostealer. The malware targets browser passwords, email credentials and crypto wallets.
PureLogs infostealer via fake order forms
FortiGuard Labs published findings on 5 June about another phishing campaign distributing the PureLogs infostealer. The attackers send deceptively authentic order forms as RAR archives. Once the victim opens the file, the hackers combine JavaScript and PowerShell to inject the malware into a legitimate system process using process hollowing – a method that conventional security software rarely detects. PureLogs specifically steals access credentials from web browsers, Discord accounts and cryptocurrency wallets.
FBI warning: Microsoft 365 compromised without password
On 4 June, the FBI raised the alarm: a fraud campaign is abusing Microsoft 365 applications such as Outlook, Teams and OneDrive. The perpetrators exploit the legitimate Microsoft sign-in system to gain access to accounts without a password, thereby also circumventing two-factor authentication (MFA).
In parallel, the phishing-as-a-service platform Kali365 has expanded its arsenal. It is now targeting Okta Single Sign-On (SSO) and the messenger service MAX Messenger, which has around 110 million users. The attackers abuse the OAuth 2.0 Device Authorization Flow to steal security tokens. They exfiltrate the stolen data via automated Telegram bots.
IronWorm compromises npm packages
The threat landscape also extends to software supply chains. Researchers discovered the IronWorm attack, which compromised 36 packages in the npm registry. The malicious code stole cloud tokens, SSH keys and cryptocurrency data from developers who integrated the infected packages into their projects.
FIFA World Cup 2026: Over 4,300 fraudulent domains
Group-IB uncovered a massive fraud ecosystem surrounding the 2026 FIFA World Cup. Since August 2025, over 4,300 fraudulent domains have been registered. The GHOST STADIUM group operates more than 300 active phishing pages that impersonate official FIFA pages and PingIdentity SSO portals. Researchers estimate the potential damage from premium ticket fraud at hundreds of millions of euros. Over 2,500 FIFA-related credentials have already appeared in darknet forums.
Autonomous AI worm infects test network
Researchers from the University of Toronto presented an autonomous worm on 4 June that is based on an open large language model. In a controlled test network with 33 hosts, the worm identified 31.3 vulnerabilities and successfully infected 23.1 systems. The malware is capable of modifying its own code in real time to bypass blacklists and establish persistence.
The study's authors recommend strong access controls such as passkeys as well as network segmentation as an effective defence against this new generation of AI-driven attacks.
Source: Google News AT — Crime (de)