home.social

#adversaryinthemiddle — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #adversaryinthemiddle, aggregated by home.social.

  1. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  2. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  3. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  4. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  5. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  6. Phishing Service BigBear Exposes 258 Firms to MFA Bypass

    BigBear 2.0, a sneaky phishing-as-a-service operation, has compromised 258 companies by bypassing multi-factor authentication (MFA) for Microsoft 365 users worldwide, swiping 5,137 credential records in the process. This cunning attack used an adversary-in-the-middle approach to intercept passwords, MFA tokens, and session cookies,…

    osintsights.com/phishing-servi

    #PhishingAsAService #MfaBypass #Microsoft365 #Evilginx2 #Adversaryinthemiddle

  7. Inside Knight Office, a New M365 AiTM Phishing Kit

    Huntress researchers discovered Knight Office, a phishing kit utilizing Adversary-in-the-Middle techniques to steal Microsoft 365 session tokens. The attack chain begins with DocuSign-themed phishing emails containing redirects through Monday.com and compromised Joomla websites. Victims are directed to credential capture pages where session tokens are harvested and fed into the Knight Office console. These stolen tokens enable attackers to bypass multi-factor authentication entirely by using already-authenticated sessions. In one incident, attackers registered rogue devices in Microsoft Entra ID and bound Windows Hello for Business credentials for persistence. Analysis revealed nine phishing attacks linked to this kit over two weeks, with hundreds of related emails reported since April. The console, hosted at IP 104.37.188.94, manages at least 25 phishing domains using .vu top-level domains.

    Pulse ID: 6a9826f70dafef0cf167f596
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #CyberSecurity #Email #InfoSec #Knight #Microsoft #OTX #Office #OpenThreatExchange #Phishing #Windows #bot #AlienVault

  8. Phishing Kit NovaCookies Exploits Docusign Notifications to Hijack Microsoft 365 Sessions

    Meet NovaCookies, a sneaky phishing kit that's being sold for just $320 a month, and can hijack your Microsoft 365 sessions in real-time by cleverly intercepting Docusign notifications. This live adversary-in-the-middle relay captures active sessions, allowing hackers to harvest your…

    osintsights.com/phishing-kit-n

    #PhishingKit #Novacookies #Microsoft365 #Adversaryinthemiddle #MultifactorAuthenticationBypass

  9. Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

    Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.

    Pulse ID: 6a84c514863d37cbadb72833
    Pulse Link: otx.alienvault.com/pulse/6a84c
    Pulse Author: AlienVault
    Created: 2026-08-18 20:48:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #AdversaryInTheMiddle #AitM #Browser #Cookies #CyberSecurity #Education #Email #HTML #InfoSec #Java #JavaScript #Manufacturing #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #Rust #SVG #Word #bot #AlienVault

  10. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  11. Greatness PhaaS Steals Microsoft 365 Tokens Despite MFA

    The Greatness Phishing-as-a-Service platform uses Adversary-in-the-Middle
    and device-code phishing to steal Microsoft 365 authentication tokens and
    bypass MFA. Active campaigns exploit trusted sender configurations and
    phishing lures to compromise accounts. Stolen tokens enable attackers to
    access Outlook, Teams, SharePoint and OneDrive while evading
    conventional authentication-based security controls.

    Pulse ID: 6a79bef48cee5cb15fd34fd2
    Pulse Link: otx.alienvault.com/pulse/6a79b
    Pulse Author: cryptocti
    Created: 2026-08-10 12:07:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #CyberSecurity #EDR #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #Rust #bot #cryptocti

  12. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust