Tag

Adversary In The Middle

All articles tagged with #adversary in the middle

Mass phishing campaign exploits enterprise lures to steal credentials from 35k users across 26 countries
technology21 days ago

Mass phishing campaign exploits enterprise lures to steal credentials from 35k users across 26 countries

Microsoft disclosed a large-scale credential-stealing phishing campaign that targeted more than 35,000 users across 26 countries (92% in the U.S.), with victims in healthcare, financial services, and other sectors. Attackers used polished, enterprise-style emails about code-of-conduct reviews, sent via legitimate email services, and embedded PDFs that led to an AiTM (adversary-in-the-middle) phishing flow to harvest Microsoft credentials and tokens and bypass MFA. Victims encounter CAPTCHA checks and multiple intermediate pages before a final sign-in page, with the destination differing by device. The report also highlights rising QR-code phishing, ongoing BEC activity, and Tycoon 2FA PhaaS infrastructure shifting hosting to evade defenses, alongside two notable Q1 campaigns and a broader surge in phishing threats (about 8.3 billion from Jan–Mar 2026).

"CISA's Tools Combat Phishing and Hacking in Microsoft Cloud"
cybersecurity3 years ago

"CISA's Tools Combat Phishing and Hacking in Microsoft Cloud"

Microsoft's Threat Intelligence team has uncovered a phishing kit that allows attackers to bypass multi-factor authentication (MFA) and mimic Microsoft Office or Outlook. The kit, which is being sold on cybercrime forums and Telegram channels, uses an adversary-in-the-middle (AitM) campaign to intercept and modify communications between a user and a website or service to steal sensitive information. The phishing kit logs in to the legitimate service using stolen credentials and forwards the MFA request to the user, who provides it. The phishing kit then proxies that information to the legitimate website, allowing the attacker to access the legitimate service as the user. Microsoft recommends deploying and maintaining MFA, enabling conditional access and Azure AD security defaults, deploying security solutions on the network, keeping software and operating systems up to date, and educating users about computer security and cybercrime to protect against this AitM threat.