As cited
Copy frozen at (site build).
threat intel
Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure
Threat actors are exploiting Railway, a Platform-as-a-Service (PaaS) offering, as infrastructure to replay stolen Microsoft 365 tokens in attacks targeting hundreds of organizations. The campaign combines adversary-in-the-middle (AiTM) tactics and device code phishing to compromise credentials across a large number of Microsoft 365 tenants and managed service providers (MSPs).
Why it matters: Organizations using Microsoft 365 and MSPs face direct risk from token replay attacks; practitioners should review authentication logs for suspicious token usage and consider disabling legacy authentication and device code flows where possible.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure
Threat actors are exploiting Railway, a Platform-as-a-Service (PaaS) offering, as infrastructure to replay stolen Microsoft 365 tokens in attacks targeting hundreds of organizations. The campaign combines adversary-in-the-middle (AiTM) tactics and device code phishing to compromise credentials across a large number of Microsoft 365 tenants and managed service providers (MSPs).
Why it matters: Organizations using Microsoft 365 and MSPs face direct risk from token replay attacks; practitioners should review authentication logs for suspicious token usage and consider disabling legacy authentication and device code flows where possible.
- Source published
- First seen by Cybersecurity Tracker