September’s attacks showed how CSuite, N0va, IronToll, Wazza, and TerminalFix blurred the line between legitimate business workflows and malicious activity by abusing trusted services, authentication flows, and infrastructure. The campaigns increased risk to Microsoft 365 users, payment data, endpoints, and enterprise identity systems while making detection and incident scoping much harder. #CSuite #N0va #IronToll #Wazza #TerminalFix #Microsoft365
Keypoints
- Attackers increasingly hid malicious activity inside trusted cloud services, document-sharing platforms, authentication flows, and remote-management software.
- CSuite combined Microsoft 365 session theft with legitimate remote management tools to expand risk to email, endpoints, and payment fraud.
- N0va used Device Code phishing to steal Microsoft 365 access and refresh tokens, extending access beyond simple password theft.
- IronToll impersonated government, postal, banking, and transport services to steal card data and OTPs in real time across 12+ countries.
- Wazza used routing, anti-bot checks, and staged redirects to conceal its final phishing page from automated detection.
- TerminalFix abused compromised WordPress sites, signed binaries, and other trusted components to deliver malicious payloads and reach C2 infrastructure.
- Security teams need cross-system correlation across identity, browser, endpoint, and network evidence to understand the full scope of these attacks.
MITRE Techniques
- [T1566 ] Phishing – Used business-themed lures and impersonated services to trick victims into interacting with fake login or document pages (‘impersonating services such as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365’).
- [T1528 ] Steal Application Access Token – N0va targeted Microsoft 365 access and refresh tokens to bypass password-only protection (‘obtain access and refresh tokens through legitimate Microsoft authentication flows’).
- [T1056 ] Input Capture – CSuite and IronToll captured credentials, card data, OTPs, and session information entered by victims (‘capture credentials and authenticated sessions’; ‘steal payment-card data and OTPs in real time’).
- [T1090 ] Proxy – Wazza and IronToll used routing and infrastructure changes to hide the final destination or rotate delivery paths (‘campaign routing and anti-bot filters’; ‘disposeable domains can rotate quickly’).
- [T1105 ] Ingress Tool Transfer – CSuite delivered remote-management tools and TerminalFix used multi-stage delivery to bring malicious components onto victim systems (‘deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect’).
- [T1219 ] Remote Access Software – CSuite abused legitimate remote-management software for persistent access (‘install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect’).
- [T1204 ] User Execution – Victims had to interact with lures, fake verification pages, or document prompts before the malicious flow continued (‘document lure, login request, signed process, or remote-management tool may look legitimate on its own’).
- [T1053 ] Scheduled Task/Job – Not explicitly stated as a task, but TerminalFix used staged execution and trusted components to run later payloads (‘later stages execute through a signed Microsoft binary’).
- [T1106 ] Native API – TerminalFix leveraged legitimate runtime and signed binaries to execute payloads in a less obvious way (‘a legitimate Node.js runtime to decode them’; ‘execute through a signed Microsoft binary’).
- [T1562 ] Impair Defenses – Wazza attempted to evade automated detection with anti-bot checks and validation gates (‘keep the final phishing page hidden until the visitor passes the required checks’).
- [T1027 ] Obfuscated Files or Information – TerminalFix hid payloads by encoding binary data as ordinary English words (‘represents binary payloads as sequences of ordinary English words’).
- [T1071 ] Application Layer Protocol – IronToll used WebSocket communications for its operator panel (‘A WebSocket-based operator panel gives attackers live visibility into victim sessions’).
- [T1102 ] Web Service – TerminalFix and others relied on cloud services and public platforms for infrastructure and lure retrieval (‘Cloudflare Workers and Linode Object Storage’; ‘a Polygon smart contract’).
- [T1583 ] Acquire Infrastructure – Attackers leveraged compromised websites and cloud services to support campaigns (‘infrastructure is distributed across compromised websites and cloud services’).
- [T1021 ] Remote Services – CSuite created remote access paths through management tools and endpoint control (‘creating paths to mailbox abuse, payment fraud, persistent remote access’).
Indicators of Compromise
- [Malware/Campaign Names ] referenced campaigns – CSuite, N0va, IronToll, Wazza, TerminalFix
- [Brands/Impersonated Services ] lure themes – Microsoft 365, Adobe, DocuSign, Zoom, Dropbox, SharePoint, OneDrive
- [Remote Management Tools ] payloads and access tools – ScreenConnect, Atera, Syncro, and PDQ Connect
- [Cloud/Hosting Services ] infrastructure used in campaigns – Cloudflare Workers, Linode Object Storage
- [Platforms/Services ] retrieval and execution support – Polygon smart contract, Node.js runtime, WordPress sites
- [Domains ] malicious infrastructure – 114 malicious domains, 71 non-Cloudflare origins, and other rotating domains
- [File/Process Names ] execution-related components – signed Microsoft binary, browser redirects, and decoded payload files
- [Identities/Tokens ] access artifacts – Microsoft 365 sessions, refresh tokens, device registrations
Read more: https://any.run/cybersecurity-blog/major-cyber-attacks-september-2026/