From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud

Post Reply
Shane1145
Posts: 1689
Joined: Wed Sep 25, 2024 2:31 pm

From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud

Post by Shane1145 »

A large-scale phishing campaign that used adversary-in-the-middle (AiTM) phishing sites stole passwords, hijacked a user’s sign-in session, and skipped the authentication process even if the user had enabled multifactor authentication (MFA). The attackers then used the stolen credentials and session cookies to access affected users’ mailboxes and perform follow-on business email compromise (BEC) campaigns against other targets. Based on our threat data, the AiTM phishing campaign attempted to target more than 10,000 organizations since September 2021.

https://www.microsoft.com/en-us/securit ... ial-fraud/
Post Reply