🚨 We identified Mir0Auth, a new phishkit targeting M365 auth tokens, with primary activity observed against US organizations. It starts with DocuSign-themed lures, then moves victims into Device Code phishing through source-code-like endpoints including /task_queue.cs, /context.go, and /window.rs, with XOR-obfuscated C2 URLs and request bodies.
👉 Review the flow and decoded network logic in ANY.RUN Sandbox
🔍 Track evolving activity using this TI Lookup query: threatName:"mir0auth"
🔹 Network chain:
Phishing page ➡️ POST /task_queue.cs beacon ➡️ POST /context.go returns a device code ➡️ the code is copied to the clipboard, and the legitimate Microsoft sign-in page at microsoft[.]com/devicelogin opens in a popup ➡️ /window.rs session polling every 3s ➡️ victim signs in ➡️ attacker session receives M365 tokens
🔹 Traffic obfuscation:
– C2 URLs are hex strings XORed with MiroAuth
– C2 bodies are JSON XORed with M1r0AuthBinProT0c0l_2024!
– Data is sent as raw application/octet-stream; responses use the same key
⚡️ Strengthen phishing detection in your SOC with ANY.RUN
Post #1291
80


- ❤ 7
- 🔥 3
- 👾 1