August’s attacks showed that attackers increasingly exploit trusted business activity, from Microsoft 365 sessions and hiring workflows to remote-management tools and business-themed files, to gain access and maintain control. The incidents involving Mirage2FA, 3DBlast, SnakeBiteAgent, the US-first RMM campaign, and Famous Chollima highlight how identity compromise, session theft, and insider-style access can expose corporate systems and intellectual property. #Mirage2FA #3DBlast #SnakeBiteAgent #FamousChollima #Microsoft365 #ANY.RUN
Keypoints
- Attackers increasingly abused trusted enterprise activity such as authentication flows, remote administration, and hiring processes.
- The US-first RMM campaign used fake business documents to trick victims into installing legitimate remote-management tools for remote access.
- Famous Chollima operatives were allegedly hired into a fake DeFi startup, exposing insider-risk concerns after onboarding.
- Mirage2FA targeted Microsoft 365 users, stealing credentials, 2FA codes, and session cookies to hijack active sessions.
- SnakeBiteAgent was delivered in a business-themed ZIP and provided attackers with remote control, credential theft, keylogging, and surveillance.
- 3DBlast impersonated Microsoft and Google login pages and used multiple phishing flows to increase account-takeover risk.
- August’s campaigns rotated infrastructure and tactics, showing that single-IOC blocking and password resets are often insufficient.
MITRE Techniques
- [T1566.001 ] Spearphishing Attachment – Victims were lured with business-themed files such as tax notices, invoices, PDFs, and ZIP archives to initiate compromise. (‘used tax documents, Social Security notices, invoices, Adobe PDFs, VAT notices, and shipping communications’ / ‘delivered inside a business-themed ZIP archive’)
- [T1219 ] Remote Access Software – Attackers abused signed RMM tools and remote-control utilities to gain hands-on access while blending in with normal administration. (‘abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian’ / ‘silent installation of AnyDesk and MeshCentral’)
- [T1078 ] Valid Accounts – False identities and legitimate permissions were used to obtain trusted access after onboarding or login. (‘once a false identity passes hiring checks, the worker can receive legitimate access’ / ‘legitimate permissions across source code repositories and internal systems’)
- [T1550.004 ] Use Alternate Authentication Material: Web Session Cookie – Stolen session cookies were used to keep access after authentication and MFA. (‘intercept credentials, 2FA codes, and authenticated session cookies’ / ‘active Microsoft 365 sessions even after users completed MFA’)
- [T1110 ] Brute Force – Not directly described as password cracking; no clear use found in the article. (‘no explicit brute-force activity was described’)
- [T1056.001 ] Keylogging – SnakeBiteAgent captured keystrokes to steal sensitive information from infected systems. (‘keylogging’)
- [T1021 ] Remote Services – Attackers relied on remote desktop software, VPNs, and remote management to interact with victim environments. (‘VPNs, remote desktop software’ / ‘receive legitimate access to source code, internal systems’)
- [T1056.001 ] Input Capture: Keylogging – SnakeBiteAgent monitored user input as part of its credential theft and surveillance features. (‘keylogging’)
- [T1113 ] Screen Capture – The malware supported hidden desktop access and surveillance, enabling observation of victim activity. (‘hidden desktop access’)
- [T1125 ] Video Capture – SnakeBiteAgent could access webcams and microphones for covert monitoring. (‘webcam and microphone capture’)
- [T1027 ] Obfuscated Files or Information – The article notes some campaigns changed infrastructure and flows rather than relying on obfuscation; no clear malware obfuscation was described. (‘no obfuscation’)
- [T1185 ] Browser Session Hijacking – Mirage2FA and 3DBlast targeted browser-based login flows to intercept and relay authentication sessions. (‘hijack active Microsoft 365 sessions’ / ‘abuse legitimate authentication processes’)
- [T1556 ] Modify Authentication Process – Attackers interfered with OAuth, device-code authentication, MFA, and login flows to bypass normal access controls. (‘targeted Microsoft 365 sessions, OAuth, device-code authentication, and MFA flows’)
- [T1566.002 ] Spearphishing Link – Phishing pages and login flows were used to impersonate Microsoft and Google services. (‘impersonating Microsoft 365, Office 365, and Google’)
- [T1105 ] Ingress Tool Transfer – Malware and remote tools were delivered through ZIP archives and installed additional remote-access software. (‘delivered inside a business-themed ZIP archive’ / ‘silent installation of AnyDesk and MeshCentral’)
- [T1071.001 ] Web Protocols – Phishing infrastructure and browser-based activity relied on web traffic and rotating URLs/domains. (‘rotating domains, phishing flows, hosting, and remote-access tools’)
- [T1090 ] Proxy – The article mentions VPNs and relay-style phishing but not explicit proxy tooling; no direct proxy technique was confirmed. (‘VPNs’)
Indicators of Compromise
- [File names / archive themes ] Business lure files used in phishing and delivery – tax documents, Social Security notices, invoices, VAT notices, shipping communications, ZIP archive
- [Software names ] Legitimate remote-management tools abused for access – GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, ITarian
- [Malware / tool names ] Remote access and phishing tools mentioned in the article – SnakeBiteAgent, Mirage2FA, 3DBlast
- [Organizations / platforms ] Services and environments targeted or referenced – Microsoft 365, Office 365, Google, AnyDesk, MeshCentral
- [Malicious domains / URLs ] Rotating phishing and delivery infrastructure – changing domains, URLs such as url:”/sw.js?tab=t*_*”
- [Network / infrastructure indicators ] Campaign infrastructure shifted frequently to evade blocking – hosting changes, remote-access tools, and other rotating infrastructure
- [Identifiers / counts ] Scope markers for the campaigns – 46 countries, over 4,000 victims in the United States
Read more: https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/