Cybercriminals Bypass MFA via Authentication Reset and Token Theft

Photo: VentureBeat
Quick answer
Киберпреступники обходят MFA через сброс аутентификации и кражу токенов. Группа Mutant Spider использует голосовой фишинг в Microsoft Teams, а платформа Kali365 автоматизирует кражу токенов Microsoft 365 за 17 887 ₽/мес.
The financial sector became the fourth most popular target for cyberattacks in the first quarter of 2026, accounting for 12% of all recorded incidents. According to a CrowdStrike report, the number of attacks involving direct adversary intervention increased by 43% over two years, and by 48% in North America. Of particular concern is the rise in activity by ransomware groups: the number of financial organizations appearing in data breach lists increased by 27% over the year.
The Mutant Spider group, a leader in attacks on financial companies, employs social engineering via Microsoft Teams. Attackers call employees, impersonating IT specialists, and persuade them to reset MFA. Afterward, attackers register their own devices on the network and gain access to corporate data. The Kali365 platform, sold on Telegram for 17 887 ₽ per month, automates the theft of Microsoft 365 tokens via legitimate OAuth flows, allowing MFA to be bypassed without hacking.
Experts note that traditional security measures, such as MFA, are ineffective against new attack methods. The 2026 Verizon report indicates that credential theft accounts for only 13% of all initial access vectors, while vulnerability exploitation has risen to 31%. The average time to remediate critical vulnerabilities has increased to 43 days, and the proportion of vulnerabilities fixed from the CISA catalog has dropped to 26%.
To protect against such attacks, experts recommend implementing additional verification measures during MFA resets, restricting OAuth flows in Entra ID, and monitoring token activity. It is also important to reassess security budgets, shifting focus from password theft protection to session and token control.
Common questions
- Как киберпреступники обходят MFA?
- Злоумышленники используют сброс учетных данных через социальную инженерию (например, голосовой фишинг в Microsoft Teams) и крадут токены через легитимные OAuth-потоки с помощью платформы Kali365.
- Какую угрозу представляет группа Mutant Spider?
- Mutant Spider — самая активная группа, атакующая финансовые организации. Она использует подмену IT-специалистов для сброса MFA и регистрации собственных устройств в корпоративной сети.
- Что такое Kali365 и как она работает?
- Kali365 — платформа за 17 887 ₽/мес, автоматизирующая кражу токенов Microsoft 365 через легитимные OAuth-потоки, что позволяет обходить MFA без взлома.
- Почему традиционные меры защиты, включая MFA, неэффективны?
- Tрадиционные меры защиты не работают против новых методов атак, так как злоумышленники эксплуатируют уязвимости (31% инцидентов) и используют легитимные потоки (OAuth) для кражи токенов.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml