
Phishing Link Could Plant a Rogue ChatGPT Agent
Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…
Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics rather than stop. The report highlights real campaigns that shifted toward Microsoft Teams-based social engineering, highly automated BEC email blasts, and multi-stage phishing using calendar invites and Microsoft login redirects to deliver malware.
After Microsoft disrupted the Tycoon2FA phishing-as-a-service platform, phishing volume tied to that service dropped 92%, including declines in QR code and CAPTCHA-gated phishing. Rather than stopping, attackers shifted tactics. One notable adaptation was using Microsoft Teams as a social engineering channel, where attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. Separately, Microsoft observed a multi-stage phishing campaign that used nested EML files, calendar invitations, and a Microsoft authentication redirect to deliver malware, abusing trusted cloud infrastructure to disguise the attack.
These campaigns succeeded by exploiting trust in familiar tools rather than obviously suspicious external senders. A Teams message from what appears to be internal IT does not carry the same skepticism as an unknown email. Similarly, calendar invites and Microsoft authentication redirects look like normal workflow steps, making it easy for a target to click through without questioning the process. On top of this, Microsoft also observed a highly automated BEC campaign using scripted emails, Amazon SES, and engagement tracking, reaching tens of thousands of users in a very short window, showing attackers can scale trust-based tactics quickly.
Organizations should not treat Teams messages as automatically safe just because they arrive on an internal platform. Employees should be trained to question unexpected calendar invites, login redirects, or file requests, even when they appear to come from legitimate-looking Microsoft 365 workflows. Microsoft recommends blocking emails containing known bad URLs or subject fields and moving toward passwordless authentication or MFA for accounts that still require passwords. Complementing email filtering with phishing-resistant authentication, such as passkeys and phishing-resistant MFA, reduces the effectiveness of credential theft attempts even when a message gets through. Because automated BEC campaigns can reach tens of thousands of users within hours, fast reporting and response to suspicious messages remain essential, particularly for finance, accounts payable, executives, and IT/service desk staff who are frequently targeted.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Microsoft reported phishing volume linked to Tycoon2FA fell 92% after the disruption, so attackers adapted by using Microsoft Teams as a new social engineering channel to build trust before stealing credentials or delivering malware.
A multi-stage campaign used nested EML files, calendar invitations, and a Microsoft authentication redirect to deliver malware, disguising the attack behind trusted Microsoft 365 infrastructure.
Microsoft observed one automated BEC campaign reach 42,000 organizations in under three hours, and another reach over 67,000 users using scripted emails and engagement tracking.
Microsoft recommends blocking known bad URLs and subject fields, and moving toward passwordless or phishing-resistant MFA to reduce the impact of credential theft attempts.
That big Tycoon2FA takedown? Phishing didn’t stop; it just moved into places we trust, like Microsoft Teams and calendar invites. Example one: you get a Teams message, “Hi, IT Helpdesk here. We need to confirm your account to resolve an access/security issue.” They chat a bit, then ask for your login or MFA code, or drop a file or link to ‘fix’ it. That’s phishing in Teams. Example two: an email says, “Please review the attached message and calendar invite for the updated details.” Inside are nested .EML files and an ICS invite. You click, get bounced through a Microsoft login screen that feels out of place, and behind that, malware. Here’s the move: if a Teams chat or email pushes you to share credentials, MFA codes, or log in when it doesn’t match the task, stop and report it to the security team immediately, fast reporting beats their automation.

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…