Cisco Talos says UAT-11985 used fake event invitations to phish Taiwanese research staff through a kit that relays Google logins and MFA challenges live. For the people those invitations target, the useful control is a second factor the relay cannot pass along.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence55
Microsoft has tracked passkey- and SSO-themed help desk impersonation since May 2026, with the calls steering employees into adversary-in-the-middle proxies and device-code grants that hand over live Microsoft 365 sessions.
Perspective Coverage
3 publishers
- Builder
- Builder 25%
- Operator
- Operator 63%
- Investor
- Investor 12%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence70
Huntress found legitimate remote management software abused in 45% of the endpoint incidents it logged in the first quarter of 2026. A rogue copy can behave like IT's approved one, so defenders have to know which tools are sanctioned and how each install arrived.
Reality
- Evidence45
- Adoption55
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Proofpoint says China-aligned TA419 has posed as a former White House official and an Anthropic employee to phish AI policy experts since at least April 2025. The first approach asks for nothing; the credential-stealing link follows only after a target replies.
Perspective Coverage
7 publishers
- Builder
- Builder 28%
- Operator
- Operator 59%
- Investor
- Investor 13%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives30
- Confidence65
buildOne report1 publisher Proofpoint says China-aligned TA419 has phished US AI policy experts since April 2025 with a proxy that captures Microsoft session cookies and bypasses MFA. Its fix is passkeys plus out-of-band checks on unsolicited expert outreach.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
buildOne report1 publisher Microsoft's 2026 Digital Defense Report puts MFA-relaying proxy kits at 44.6% of phishing techniques, as phishing rose to 23% of its incident cases. SMS codes and push approvals pass straight through those proxies, so protecting company email now means passkeys or FIDO2 keys, starting with admins and finance staff.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence55
Arctic Wolf says the cluster it tracks as PREY-0058 deploys no malware at all. A call from fake IT leads to a proxied login page, and the stolen session token comes back from inside the victim's own ASN.
Perspective Coverage
3 publishers
- Builder
- Builder 17%
- Operator
- Operator 75%
- Investor
- Investor 8%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence60
CloudSEK took administrator access to the panel and counted 5,137 stolen records coming off 42 VPS nodes into five leasing affiliates' Telegram bots, with the phishing pages dark for three weeks while the panel itself stays reachable.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 60%
- Investor
- Investor 10%
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives40
- Confidence60
Island says the adversary-in-the-middle service runs on at least 755 domains against hundreds of organizations. The session it steals arrives after an authentication the identity provider records as entirely normal.
Reality
- Evidence45
- Adoption58
- Hype gap+18
- Incentives65
- Confidence55
Microsoft has tracked intrusions since May in which callers posing as IT told employees a passkey update was due, then steered them to a phishing page or a device-code prompt. The enrollment step is where the chain starts.
Reality
- Evidence55
- Adoption35
- Hype gap−5
- Incentives60
- Confidence58
buildOne report1 publisher Microsoft Security Research describes callers posing as IT staff to get a Microsoft 365 session relayed or minted to their own client. The lasting damage comes from the MFA method they then register.
Reality
- Evidence55
- Adoption40
- Hype gap+15
- Incentives55
- Confidence55
CloudSEK got inside the BigBear 2.0 administrative panel and found more captured Microsoft 365 session cookies than plaintext passwords, along with code written to switch FIDO2 off on the phishing pages.
Reality
- Evidence55
- Adoption58
- Hype gap+12
- Incentives72
- Confidence56
Since May, intruders posing as IT have walked employees through a passkey update on their personal phones, then registered their own authentication method and pulled mail and files through Graph, SharePoint and Exchange APIs.
Reality
- Evidence62
- Adoption32
- Hype gap+12
- Incentives65
- Confidence58
A week of takedowns removed people and froze assets across five separate actions, while the kit that manufactures the stolen Microsoft 365 sessions those crews depend on still sells on Telegram for $320 a month.
Reality
- Evidence28
- Adoption52
- Hype gap+30
- Incentives58
- Confidence36
buildOne report1 publisher Island's write-up describes an adversary-in-the-middle proxy that hands passwords, push approvals and SMS codes to real Microsoft servers, then keeps the cookie Microsoft issues. Origin binding is the only listed control that breaks it.
Reality
- Evidence48
- Adoption40
- Hype gap+18
- Incentives66
- Confidence47
Island says the kit relays Microsoft 365 sign-ins behind genuine Docusign envelopes and legitimate Microsoft or Google redirects, leaving sender reputation nothing to grade.
Reality
- Evidence60
- Adoption58
- Hype gap+18
- Incentives74
- Confidence62