RMON Networks Security Advisory
What You Need to Know
How the Attack Works
Step 1: The Phone Call
Internal IT Support
Microsoft Support
Security Operations
Help Desk Personnel
Step 2: The Fake Website
Mimics Microsoft Entra ID
Uses company branding
Looks nearly identical to legitimate Microsoft sign-in pages
Requests Microsoft 365 credentials and MFA approval [securityweek.com], [bleepingcomputer.com], [windowsreport.com]
Step 3: Account Compromise
Captures authentication information
Guides the user through MFA approval
Registers an attacker-controlled passkey
Gains persistent access to the Microsoft 365 account [securityweek.com], [bleepingcomputer.com], [thehackernews.com]
Step 4: Data Theft
Email
SharePoint
OneDrive
Teams files
Sensitive business documents
Warning Signs Your Team Should Know
What Employees Should Do
STOP
VERIFY
NEVER
Share MFA codes
Approve unexpected authentication prompts
Register new authentication methods at a caller's request
Enter credentials on websites provided during unsolicited calls
Recommended Security Controls
If You Suspect a Compromise
You approved an unexpected MFA request
You entered credentials after receiving a security-related phone call
You registered a passkey or authentication method at someone's direction
You notice unusual account activity