CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Inside Knight Office, a New M365 AiTM Phishing Kit

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5595

As cited

Copy frozen at (site build).

threat intel

Inside Knight Office, a New M365 AiTM Phishing Kit

Knight Office is a newly discovered phishing kit designed to target Microsoft 365 (M365) using account-in-the-middle (AiTM) techniques. The kit features custom control panels and integrates Cloudflare Turnstile to bypass security checks while stealing M365 tokens from victims.

Why it matters: Security teams defending M365 environments need to monitor for Knight Office campaigns, as AiTM phishing kits allow attackers to bypass multifactor authentication (MFA) and obtain session tokens that grant full account access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Inside Knight Office, a New M365 AiTM Phishing Kit

Knight Office is a newly discovered phishing kit designed to target Microsoft 365 (M365) using account-in-the-middle (AiTM) techniques. The kit features custom control panels and integrates Cloudflare Turnstile to bypass security checks while stealing M365 tokens from victims.

Why it matters: Security teams defending M365 environments need to monitor for Knight Office campaigns, as AiTM phishing kits allow attackers to bypass multifactor authentication (MFA) and obtain session tokens that grant full account access.

VendorsMicrosoftCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary