Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business 0 followers
Follow
Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat

Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat

Jul 1, 2026 • 13min 38s

Episode description

Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat

The Gentlemen ransomware group has emerged as a top-ten global threat actor by deploying zero-day driver exploits to disable endpoint security tools before launching encryption attacks. Using a vulnerable Kontron driver and the Bring Your Own Vulnerable Driver technique, the group neutralises detection systems silently, often gaining hours of undetected access through compromised VPN and firewall appliances. Meanwhile, the ARToken phishing-as-a-service platform automates Microsoft 365 account takeover through device code phishing and Primary Refresh Token persistence. Standard multi-factor authentication does not prevent these attacks, as the OAuth authentication flows are legitimate. The platform includes automated email and SharePoint exfiltration, plus integrated business email compromise tooling that industrialises payment redirection fraud. UK small businesses using Microsoft 365 face direct exposure, particularly in professional services, accountancy, and financial sectors where client data and payment processes rely on email systems. The NCSC has published guidance on restricting device code flow and monitoring for these attacks, yet implementation remains inconsistent even in critical national infrastructure environments.

Chapters

  • Introduction Overview of two urgent threat developments: a ransomware group defeating endpoint security and an automated Microsoft 365 phishing platform bypassing multi-factor authentication.
  • The Gentlemen Ransomware Group and Zero-Day Driver Exploits Analysis of The Gentlemen’s rise to top-ten threat status through Bring Your Own Vulnerable Driver techniques, their use of a Kontron driver zero-day to disable endpoint protection, and their systematic approach to network reconnaissance and ransomware deployment.
  • Call to Action Encouragement to share the briefing and subscribe for daily updates.
  • ARToken: Automated Microsoft 365 Account Takeover Detailed examination of the ARToken phishing-as-a-service platform, its device code phishing methodology, Primary Refresh Token persistence, automated data exfiltration, and integrated business email compromise workflows that bypass standard MFA.
  • NCSC Penetration Testing Findings Brief discussion of persistent security gaps identified in critical national infrastructure, including default credentials, insufficient segmentation, and poor patch management.
  • Closing Recommendations Summary of immediate actions: enable tamper protection, verify monitoring procedures, restrict device code flow in Microsoft 365, and implement out-of-band payment verification.

Links

  • https://securelist.com/the-gentlemen-ransomware-group/
  • https://expel.com/blog/
  • https://www.ncsc.gov.uk/guidance/bring-your-own-vulnerable-driver
  • https://blog.talosintelligence.com/artoken-phishing-as-a-service/
  • https://www.ncsc.gov.uk/guidance/device-code-flow
  • https://www.ncsc.gov.uk/blog-post/pen-testing-critical-national-infrastructure
Comments0 Activity1 Chapters0 Transcript–
Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business @ThreatAnalysis Jul 1, 2026
13:38 Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat
Jul 1, 2026
Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat
0 0 0
RSS Podcast feed
HomeLinksCreditsMap

Powered by Castopod

Persons