Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk

Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk
August’s attacks showed that attackers increasingly exploit trusted business activity, from Microsoft 365 sessions and hiring workflows to remote-management tools and business-themed files, to gain access and maintain control. The incidents involving Mirage2FA, 3DBlast, SnakeBiteAgent, the US-first RMM campaign, and Famous Chollima highlight how identity compromise, session theft, and insider-style access can expose corporate systems and intellectual property. #Mirage2FA #3DBlast #SnakeBiteAgent #FamousChollima #Microsoft365 #ANY.RUN

Keypoints

  • Attackers increasingly abused trusted enterprise activity such as authentication flows, remote administration, and hiring processes.
  • The US-first RMM campaign used fake business documents to trick victims into installing legitimate remote-management tools for remote access.
  • Famous Chollima operatives were allegedly hired into a fake DeFi startup, exposing insider-risk concerns after onboarding.
  • Mirage2FA targeted Microsoft 365 users, stealing credentials, 2FA codes, and session cookies to hijack active sessions.
  • SnakeBiteAgent was delivered in a business-themed ZIP and provided attackers with remote control, credential theft, keylogging, and surveillance.
  • 3DBlast impersonated Microsoft and Google login pages and used multiple phishing flows to increase account-takeover risk.
  • August’s campaigns rotated infrastructure and tactics, showing that single-IOC blocking and password resets are often insufficient.

MITRE Techniques

  • [T1566.001 ] Spearphishing Attachment – Victims were lured with business-themed files such as tax notices, invoices, PDFs, and ZIP archives to initiate compromise. (‘used tax documents, Social Security notices, invoices, Adobe PDFs, VAT notices, and shipping communications’ / ‘delivered inside a business-themed ZIP archive’)
  • [T1219 ] Remote Access Software – Attackers abused signed RMM tools and remote-control utilities to gain hands-on access while blending in with normal administration. (‘abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian’ / ‘silent installation of AnyDesk and MeshCentral’)
  • [T1078 ] Valid Accounts – False identities and legitimate permissions were used to obtain trusted access after onboarding or login. (‘once a false identity passes hiring checks, the worker can receive legitimate access’ / ‘legitimate permissions across source code repositories and internal systems’)
  • [T1550.004 ] Use Alternate Authentication Material: Web Session Cookie – Stolen session cookies were used to keep access after authentication and MFA. (‘intercept credentials, 2FA codes, and authenticated session cookies’ / ‘active Microsoft 365 sessions even after users completed MFA’)
  • [T1110 ] Brute Force – Not directly described as password cracking; no clear use found in the article. (‘no explicit brute-force activity was described’)
  • [T1056.001 ] Keylogging – SnakeBiteAgent captured keystrokes to steal sensitive information from infected systems. (‘keylogging’)
  • [T1021 ] Remote Services – Attackers relied on remote desktop software, VPNs, and remote management to interact with victim environments. (‘VPNs, remote desktop software’ / ‘receive legitimate access to source code, internal systems’)
  • [T1056.001 ] Input Capture: Keylogging – SnakeBiteAgent monitored user input as part of its credential theft and surveillance features. (‘keylogging’)
  • [T1113 ] Screen Capture – The malware supported hidden desktop access and surveillance, enabling observation of victim activity. (‘hidden desktop access’)
  • [T1125 ] Video Capture – SnakeBiteAgent could access webcams and microphones for covert monitoring. (‘webcam and microphone capture’)
  • [T1027 ] Obfuscated Files or Information – The article notes some campaigns changed infrastructure and flows rather than relying on obfuscation; no clear malware obfuscation was described. (‘no obfuscation’)
  • [T1185 ] Browser Session Hijacking – Mirage2FA and 3DBlast targeted browser-based login flows to intercept and relay authentication sessions. (‘hijack active Microsoft 365 sessions’ / ‘abuse legitimate authentication processes’)
  • [T1556 ] Modify Authentication Process – Attackers interfered with OAuth, device-code authentication, MFA, and login flows to bypass normal access controls. (‘targeted Microsoft 365 sessions, OAuth, device-code authentication, and MFA flows’)
  • [T1566.002 ] Spearphishing Link – Phishing pages and login flows were used to impersonate Microsoft and Google services. (‘impersonating Microsoft 365, Office 365, and Google’)
  • [T1105 ] Ingress Tool Transfer – Malware and remote tools were delivered through ZIP archives and installed additional remote-access software. (‘delivered inside a business-themed ZIP archive’ / ‘silent installation of AnyDesk and MeshCentral’)
  • [T1071.001 ] Web Protocols – Phishing infrastructure and browser-based activity relied on web traffic and rotating URLs/domains. (‘rotating domains, phishing flows, hosting, and remote-access tools’)
  • [T1090 ] Proxy – The article mentions VPNs and relay-style phishing but not explicit proxy tooling; no direct proxy technique was confirmed. (‘VPNs’)

Indicators of Compromise

  • [File names / archive themes ] Business lure files used in phishing and delivery – tax documents, Social Security notices, invoices, VAT notices, shipping communications, ZIP archive
  • [Software names ] Legitimate remote-management tools abused for access – GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, ITarian
  • [Malware / tool names ] Remote access and phishing tools mentioned in the article – SnakeBiteAgent, Mirage2FA, 3DBlast
  • [Organizations / platforms ] Services and environments targeted or referenced – Microsoft 365, Office 365, Google, AnyDesk, MeshCentral
  • [Malicious domains / URLs ] Rotating phishing and delivery infrastructure – changing domains, URLs such as url:”/sw.js?tab=t*_*”
  • [Network / infrastructure indicators ] Campaign infrastructure shifted frequently to evade blocking – hosting changes, remote-access tools, and other rotating infrastructure
  • [Identifiers / counts ] Scope markers for the campaigns – 46 countries, over 4,000 victims in the United States


Read more: https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/