The FBI dropped a warning this week with a detail worth dwelling on. Silent Ransom Group, the crew also known as Luna Moth, has stopped bothering with elaborate phishing flows at law firms. They’re driving over, putting on a polo, and asking the receptionist to let them fix something. That’s the attack. A human walking into your office, claiming to be IT, and being handed a workstation. Every cybersecurity program built around perimeter assumptions and MFA backstops just got reminded that attackers will route around your controls in whatever way is cheapest. Right now, that includes the lobby.
The lobby is part of your cyber security perimeter now
Silent Ransom Group has been working since at least 2022, and law firms are their bread and butter. The pivot to in-person impersonation is what makes this story matter. Per the FBI alert, operators show up claiming to provide tech support, get put in front of a machine, and from there they’re inside with hands on a keyboard. No malicious attachment. No callback. No drive-by. Just the oldest trick in the book wrapped in a clipboard.
If your threat model assumes the building is a soft trust boundary, you’re already losing. Most security awareness training focuses on email, links, and phone calls. Almost none of it covers the person standing at reception saying their ticket number. Reception staff are not part of incident response planning. They have no escalation path for “this guy says he’s from MSP X, should I let him in?” That gap is the entire attack.
This isn’t just law firms. Healthcare, insurance, and finance have all been targets, and the playbook scales to any office where IT vendors are normal and visitor policies are loose. The cost of trying is a polo shirt and gas money.
Meanwhile Kali365 is eating MFA for breakfast
If physical access feels too crude, the Kali365 phishing kit is the other end of the spectrum. The FBI flagged it this week through Malwarebytes’ coverage: a phishing-as-a-service kit that grabs Microsoft credentials, intercepts the MFA challenge, and gives attackers long-lived access to Outlook, Teams, and OneDrive. The selling point isn’t that it phishes well. The selling point is that it makes MFA irrelevant.
The pattern is now consistent across kits. Adversary-in-the-middle proxy, session token capture, persistence via OAuth grants and app passwords. By the time the user realizes the page looked wrong, the operator already owns a refresh token that’s good for weeks. Your conditional access policy doesn’t fire because the session looks legitimate. Your SOC sees a user logging in from a normal-looking IP because the proxy is in a clean ASN. The control you spent two years rolling out is silently sidestepped.
This is the same threat-protection failure mode that’s been compounding for a year. MFA stops password spray and credential stuffing. It does not stop somebody who phished a live session. Anyone treating MFA as a finish line is defending a perimeter that’s already breached.
Even the conference talk submission tool got popped
For the third thread, look at Pretalx. SecurityWeek covered Novee’s discovery of an account takeover vulnerability in the open-source CFP management tool used by a lot of conferences. The headline detail is funny: a researcher could give themselves a 100% acceptance rate by taking over reviewer accounts. The implication isn’t funny. If the account in your weirdest, lowest-priority SaaS app can be taken over, you’re going to find out that account has access to things you forgot about: contact lists, draft talks, internal deliberations, sometimes payment info.
The pattern across all three stories: attackers are targeting account ownership at whatever layer is cheapest. Physical lobby walkthrough. MFA-bypassing proxy. Application-layer account takeover. The identity stack you’re defending isn’t one perimeter. It’s a dozen overlapping ones, and your weakest layer is the one you haven’t audited.
What to do this week, this quarter, and ongoing
The defensive work here is unglamorous and very doable. Stop chasing the next authentication factor. Tighten the controls around what happens after someone is authenticated, and harden the boundaries you’ve been ignoring.
Right now, this week:
- Brief reception and office managers on the SRG playbook. Hand them a simple rule: any external IT vendor must be on a pre-approved list with a known contact, confirmed by callback to a number on file. No exceptions, no “we’ll just let them sit in the conference room while we check.”
- Inventory every active OAuth grant and app password against your Microsoft and Google tenants. Most environments have hundreds of stale tokens nobody remembers approving. Anything you don’t recognize, revoke now.
- Reduce session and refresh token lifetimes for privileged users. If a Kali365 operator phishes a session, the question is how many hours of access they get, not whether they get any.
- Hunt for impossible reuse: tokens or sessions used from two ASNs within minutes, conditional access policy matches that should have failed, sign-ins from compliant-but-unmanaged devices.
For the quarter, fund the work nobody pitches as exciting. Visitor management with photo capture and same-day badge expiry. Reception escalation playbooks with a real phone tree. Phishing-resistant authentication (passkeys, FIDO2) for admins and anyone with email forwarding rights. Tighten consent policies so users can’t grant OAuth scopes to unverified apps. Run an incident response tabletop where the trigger is “a person walked into the office at 2 PM claiming to be from your MSP.” Watch how badly that goes.
Ongoing, treat identity behavior as a first-class detection surface. Brute-force and password spray attempts on your edge are still happening every minute of every day, and a firewall config that drops obvious noise frees your SOC to look at the subtle stuff. The subtle stuff is where session theft lives. Behavioral baselines, first-seen device alerts, OAuth grant deltas, mailbox rule changes, and unusual MFA fatigue patterns are the signal. Security hardening at this layer pays better dividends than another EDR migration.
And bake physical incident response into your IR plan. If somebody plugged into a workstation in your office for 20 minutes, that machine is burned, that session is burned, and any credentials cached on it are burned. Treat it the same way you’d treat a stolen domain admin laptop. The fact that they walked out the front door instead of phishing in doesn’t change the blast radius.
Sources
- Hackers are knocking on office doors pretending to be IT staff (Help Net Security)
- Kali365 phishing kit bypasses MFA and steals Microsoft logins (Malwarebytes)
- Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate (SecurityWeek)
- FBI’s 2025 Internet Crime Report (Schneier on Security)
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
