home.social

#adversaryinthemiddle — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #adversaryinthemiddle, aggregated by home.social.

  1. Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms

    A widespread IT impersonation and voice-phishing campaign designated PREY-0058 is actively targeting Microsoft 365 and SaaS platforms. Threat actors impersonate IT helpdesk staff via phone or text to trick executives and senior personnel into divulging credentials through adversary-in-the-middle phishing portals. After bypassing multi-factor authentication, attackers conduct rapid automated data exfiltration across email, file storage, and cloud repositories without deploying ransomware. The operation relies heavily on NodeMaven residential proxy infrastructure to blend with legitimate traffic. Extortion demands are delivered via TOX messaging within hours of compromise, typically with 72-hour deadlines and threats of public data exposure. The campaign exhibits tradecraft overlapping with UNC6671 and involves multiple extortionware brands including BlackFile, Redact, Pink, and Helix.

    Pulse ID: 6aa2affe4ab7ba9012836da5
    Pulse Link: otx.alienvault.com/pulse/6aa2a
    Pulse Author: AlienVault
    Created: 2026-09-10 13:26:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #DataTheft #Email #Extortion #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RansomWare #bot #AlienVault

  2. Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms

    A widespread IT impersonation and voice-phishing campaign designated PREY-0058 is actively targeting Microsoft 365 and SaaS platforms. Threat actors impersonate IT helpdesk staff via phone or text to trick executives and senior personnel into divulging credentials through adversary-in-the-middle phishing portals. After bypassing multi-factor authentication, attackers conduct rapid automated data exfiltration across email, file storage, and cloud repositories without deploying ransomware. The operation relies heavily on NodeMaven residential proxy infrastructure to blend with legitimate traffic. Extortion demands are delivered via TOX messaging within hours of compromise, typically with 72-hour deadlines and threats of public data exposure. The campaign exhibits tradecraft overlapping with UNC6671 and involves multiple extortionware brands including BlackFile, Redact, Pink, and Helix.

    Pulse ID: 6aa2affe4ab7ba9012836da5
    Pulse Link: otx.alienvault.com/pulse/6aa2a
    Pulse Author: AlienVault
    Created: 2026-09-10 13:26:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #DataTheft #Email #Extortion #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RansomWare #bot #AlienVault

  3. Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms

    A widespread IT impersonation and voice-phishing campaign designated PREY-0058 is actively targeting Microsoft 365 and SaaS platforms. Threat actors impersonate IT helpdesk staff via phone or text to trick executives and senior personnel into divulging credentials through adversary-in-the-middle phishing portals. After bypassing multi-factor authentication, attackers conduct rapid automated data exfiltration across email, file storage, and cloud repositories without deploying ransomware. The operation relies heavily on NodeMaven residential proxy infrastructure to blend with legitimate traffic. Extortion demands are delivered via TOX messaging within hours of compromise, typically with 72-hour deadlines and threats of public data exposure. The campaign exhibits tradecraft overlapping with UNC6671 and involves multiple extortionware brands including BlackFile, Redact, Pink, and Helix.

    Pulse ID: 6aa2affe4ab7ba9012836da5
    Pulse Link: otx.alienvault.com/pulse/6aa2a
    Pulse Author: AlienVault
    Created: 2026-09-10 13:26:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #DataTheft #Email #Extortion #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RansomWare #bot #AlienVault

  4. Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms

    A widespread IT impersonation and voice-phishing campaign designated PREY-0058 is actively targeting Microsoft 365 and SaaS platforms. Threat actors impersonate IT helpdesk staff via phone or text to trick executives and senior personnel into divulging credentials through adversary-in-the-middle phishing portals. After bypassing multi-factor authentication, attackers conduct rapid automated data exfiltration across email, file storage, and cloud repositories without deploying ransomware. The operation relies heavily on NodeMaven residential proxy infrastructure to blend with legitimate traffic. Extortion demands are delivered via TOX messaging within hours of compromise, typically with 72-hour deadlines and threats of public data exposure. The campaign exhibits tradecraft overlapping with UNC6671 and involves multiple extortionware brands including BlackFile, Redact, Pink, and Helix.

    Pulse ID: 6aa2affe4ab7ba9012836da5
    Pulse Link: otx.alienvault.com/pulse/6aa2a
    Pulse Author: AlienVault
    Created: 2026-09-10 13:26:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #DataTheft #Email #Extortion #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RansomWare #bot #AlienVault

  5. Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms

    A widespread IT impersonation and voice-phishing campaign designated PREY-0058 is actively targeting Microsoft 365 and SaaS platforms. Threat actors impersonate IT helpdesk staff via phone or text to trick executives and senior personnel into divulging credentials through adversary-in-the-middle phishing portals. After bypassing multi-factor authentication, attackers conduct rapid automated data exfiltration across email, file storage, and cloud repositories without deploying ransomware. The operation relies heavily on NodeMaven residential proxy infrastructure to blend with legitimate traffic. Extortion demands are delivered via TOX messaging within hours of compromise, typically with 72-hour deadlines and threats of public data exposure. The campaign exhibits tradecraft overlapping with UNC6671 and involves multiple extortionware brands including BlackFile, Redact, Pink, and Helix.

    Pulse ID: 6aa2affe4ab7ba9012836da5
    Pulse Link: otx.alienvault.com/pulse/6aa2a
    Pulse Author: AlienVault
    Created: 2026-09-10 13:26:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #DataTheft #Email #Extortion #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RansomWare #bot #AlienVault

  6. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  7. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  8. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  9. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  10. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  11. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  12. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  13. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  14. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault

  15. Tracking BigBear 2.0 Evilginx2 Phishing Campaign

    In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

    Pulse ID: 6a9ef10da8f75f1218af678c
    Pulse Link: otx.alienvault.com/pulse/6a9ef
    Pulse Author: AlienVault
    Created: 2026-09-07 17:14:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cookies #CyberSecurity #InfoSec #Java #JavaScript #MFA #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #Proxy #RAT #Telegram #Vultr #Word #bot #AlienVault