home.social

#adversaryinthemiddle — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #adversaryinthemiddle, aggregated by home.social.

  1. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  2. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  3. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  4. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  5. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  6. Phishing Service BigBear Exposes 258 Firms to MFA Bypass

    BigBear 2.0, a sneaky phishing-as-a-service operation, has compromised 258 companies by bypassing multi-factor authentication (MFA) for Microsoft 365 users worldwide, swiping 5,137 credential records in the process. This cunning attack used an adversary-in-the-middle approach to intercept passwords, MFA tokens, and session cookies,…

    osintsights.com/phishing-servi

    #PhishingAsAService #MfaBypass #Microsoft365 #Evilginx2 #Adversaryinthemiddle

  7. Inside Knight Office, a New M365 AiTM Phishing Kit

    Huntress researchers discovered Knight Office, a phishing kit utilizing Adversary-in-the-Middle techniques to steal Microsoft 365 session tokens. The attack chain begins with DocuSign-themed phishing emails containing redirects through Monday.com and compromised Joomla websites. Victims are directed to credential capture pages where session tokens are harvested and fed into the Knight Office console. These stolen tokens enable attackers to bypass multi-factor authentication entirely by using already-authenticated sessions. In one incident, attackers registered rogue devices in Microsoft Entra ID and bound Windows Hello for Business credentials for persistence. Analysis revealed nine phishing attacks linked to this kit over two weeks, with hundreds of related emails reported since April. The console, hosted at IP 104.37.188.94, manages at least 25 phishing domains using .vu top-level domains.

    Pulse ID: 6a9826f70dafef0cf167f596
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #CyberSecurity #Email #InfoSec #Knight #Microsoft #OTX #Office #OpenThreatExchange #Phishing #Windows #bot #AlienVault

  8. Inside Knight Office, a New M365 AiTM Phishing Kit

    Huntress researchers discovered Knight Office, a phishing kit utilizing Adversary-in-the-Middle techniques to steal Microsoft 365 session tokens. The attack chain begins with DocuSign-themed phishing emails containing redirects through Monday.com and compromised Joomla websites. Victims are directed to credential capture pages where session tokens are harvested and fed into the Knight Office console. These stolen tokens enable attackers to bypass multi-factor authentication entirely by using already-authenticated sessions. In one incident, attackers registered rogue devices in Microsoft Entra ID and bound Windows Hello for Business credentials for persistence. Analysis revealed nine phishing attacks linked to this kit over two weeks, with hundreds of related emails reported since April. The console, hosted at IP 104.37.188.94, manages at least 25 phishing domains using .vu top-level domains.

    Pulse ID: 6a9826f70dafef0cf167f596
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #CyberSecurity #Email #InfoSec #Knight #Microsoft #OTX #Office #OpenThreatExchange #Phishing #Windows #bot #AlienVault

  9. Inside Knight Office, a New M365 AiTM Phishing Kit

    Huntress researchers discovered Knight Office, a phishing kit utilizing Adversary-in-the-Middle techniques to steal Microsoft 365 session tokens. The attack chain begins with DocuSign-themed phishing emails containing redirects through Monday.com and compromised Joomla websites. Victims are directed to credential capture pages where session tokens are harvested and fed into the Knight Office console. These stolen tokens enable attackers to bypass multi-factor authentication entirely by using already-authenticated sessions. In one incident, attackers registered rogue devices in Microsoft Entra ID and bound Windows Hello for Business credentials for persistence. Analysis revealed nine phishing attacks linked to this kit over two weeks, with hundreds of related emails reported since April. The console, hosted at IP 104.37.188.94, manages at least 25 phishing domains using .vu top-level domains.

    Pulse ID: 6a9826f70dafef0cf167f596
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #CyberSecurity #Email #InfoSec #Knight #Microsoft #OTX #Office #OpenThreatExchange #Phishing #Windows #bot #AlienVault

  10. Inside Knight Office, a New M365 AiTM Phishing Kit

    Huntress researchers discovered Knight Office, a phishing kit utilizing Adversary-in-the-Middle techniques to steal Microsoft 365 session tokens. The attack chain begins with DocuSign-themed phishing emails containing redirects through Monday.com and compromised Joomla websites. Victims are directed to credential capture pages where session tokens are harvested and fed into the Knight Office console. These stolen tokens enable attackers to bypass multi-factor authentication entirely by using already-authenticated sessions. In one incident, attackers registered rogue devices in Microsoft Entra ID and bound Windows Hello for Business credentials for persistence. Analysis revealed nine phishing attacks linked to this kit over two weeks, with hundreds of related emails reported since April. The console, hosted at IP 104.37.188.94, manages at least 25 phishing domains using .vu top-level domains.

    Pulse ID: 6a9826f70dafef0cf167f596
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #CyberSecurity #Email #InfoSec #Knight #Microsoft #OTX #Office #OpenThreatExchange #Phishing #Windows #bot #AlienVault

  11. Inside Knight Office, a New M365 AiTM Phishing Kit

    Huntress researchers discovered Knight Office, a phishing kit utilizing Adversary-in-the-Middle techniques to steal Microsoft 365 session tokens. The attack chain begins with DocuSign-themed phishing emails containing redirects through Monday.com and compromised Joomla websites. Victims are directed to credential capture pages where session tokens are harvested and fed into the Knight Office console. These stolen tokens enable attackers to bypass multi-factor authentication entirely by using already-authenticated sessions. In one incident, attackers registered rogue devices in Microsoft Entra ID and bound Windows Hello for Business credentials for persistence. Analysis revealed nine phishing attacks linked to this kit over two weeks, with hundreds of related emails reported since April. The console, hosted at IP 104.37.188.94, manages at least 25 phishing domains using .vu top-level domains.

    Pulse ID: 6a9826f70dafef0cf167f596
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #CyberSecurity #Email #InfoSec #Knight #Microsoft #OTX #Office #OpenThreatExchange #Phishing #Windows #bot #AlienVault