#aitm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #aitm, aggregated by home.social.
-
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.
Pulse ID: 6a84c514863d37cbadb72833
Pulse Link: https://otx.alienvault.com/pulse/6a84c514863d37cbadb72833
Pulse Author: AlienVault
Created: 2026-08-18 20:48:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #AdversaryInTheMiddle #AitM #Browser #Cookies #CyberSecurity #Education #Email #HTML #InfoSec #Java #JavaScript #Manufacturing #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #Rust #SVG #Word #bot #AlienVault
-
Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails
Indicators extracted from public reporting. Source: https://arcticwolf.com/resources/blog/payroll-pirates-strange-new-tides-in-business-email-compromise/
Pulse ID: 6a79a0380064469905c39916
Pulse Link: https://otx.alienvault.com/pulse/6a79a0380064469905c39916
Pulse Author: CyberHunter_NL
Created: 2026-08-10 09:56:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #CyberHunter_NL
-
UNC6671 non è mai morta: dietro Redact, Pink, Helix e Falcon c’è sempre BlackFile
Google Threat Intelligence Group svela come il gruppo di estorsione UNC6671, dato per chiuso a maggio con il ritiro del brand BlackFile, sia in realtà proseguito sotto quattro nuove insegne. Vishing mirato, phishing AiTM e furto di dati SaaS colpiscono private equity, hedge fund e big della finanza globale. -
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Indicators extracted from public reporting. Source: https://arcticwolf.com/resources/blog/payroll-pirates-strange-new-tides-in-business-email-compromise/
Pulse ID: 6a75ba1ded6ccee05f831c5d
Pulse Link: https://otx.alienvault.com/pulse/6a75ba1ded6ccee05f831c5d
Pulse Author: CyberHunter_NL
Created: 2026-08-07 10:57:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #CyberHunter_NL
-
Payroll Pirates: Strange New Tides in Business Email Compromise
Arctic Wolf is tracking an active, widespread phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle (AiTM) techniques. The operation employs voicemail-themed phishing emails that redirect victims through multiple legitimate services to AiTM proxy infrastructure, which intercepts authentication sessions even when multi-factor authentication is enabled. Once compromised, threat actors use residential proxies to maintain access, conducting automated sign-ins at eight-hour intervals while collecting email from personnel involved in financial workflows. The campaign uses Microsoft Graph for reconnaissance targeting payroll, HR, and finance users, followed by coordinated mailbox collection. Activity affects organizations across healthcare, education, manufacturing, government, and professional services sectors in the United States, Canada, and Europe. The campaign shares characteristics with Microsoft-tracked Storm-2755 activity cluster.
Pulse ID: 6a7546d2694489fe6ddddcd5
Pulse Link: https://otx.alienvault.com/pulse/6a7546d2694489fe6ddddcd5
Pulse Author: AlienVault
Created: 2026-08-07 02:45:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #AitM #Canada #CyberSecurity #Education #Email #Europe #Government #Healthcare #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RCE #UnitedStates #bot #AlienVault
-
Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts
Indicators extracted from public reporting. Source: https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
Pulse ID: 6a734f29adb20c14f4081778
Pulse Link: https://otx.alienvault.com/pulse/6a734f29adb20c14f4081778
Pulse Author: CyberHunter_NL
Created: 2026-08-05 14:56:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL
-
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Indicators extracted from public reporting. Source: https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
Pulse ID: 6a7227e3d5fa0bf81d2044b3
Pulse Link: https://otx.alienvault.com/pulse/6a7227e3d5fa0bf81d2044b3
Pulse Author: CyberHunter_NL
Created: 2026-08-04 17:56:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AitM #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL
-
We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages.
The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties.
What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands.
⛔ usersatisfactionlab[.]de
⛔ assessmentevaluationreport[.]com
⛔ duemineral[.]uk
https://www.infoblox.com/blog/threat-intelligence/the-procurement-trap-inside-an-aitm-campaign-targeting-global-institutions/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga -
Operation Olympus Blade: BKA e FBI smantellano Kratos, il phishing-as-a-service da 1.800 clienti in 35 paesi
Le autorità tedesche e statunitensi hanno sequestrato oltre 200 server e arrestato in Indonesia lo sviluppatore di Kratos, piattaforma PhaaS con tecniche AiTM usata da 1.800 clienti per 15.000 campagne di phishing al mese contro account Microsoft 365. -
Waarschuwing voor "Browser in the Browser" aanvallen
Bij een BitB-aanval toont een nepwebsite een nep pop-up-venster dat eruit ziet als een (deels of geheel) nieuw browser-venster. Gesuggereerd wordt dat u uw inloggegevens moet invoeren op bijvoorbeeld:
https:⧸⧸accounts.google.com/signin/v3/
maar dat is allemaal fake: door u ingevoerde nloggegevens vallen zo in handen van de eigenaar van de onderliggende website, die daarmee als u kan inloggen en uw account kan kapen.
Onderin https://gist.github.com/BushidoUK/57c38d5ee75481fb237e968a537de778 ziet u een lijst van criminele domeinnamen waar deze techniek op werd of nog wordt toegepast.
De hieronder getoonde website is gehost bij Amazon (zie het RELATIONS tabblad van https://www.virustotal.com/gui/domain/marriott-hiring.com). Als u zou openen (dat raad ik af):
https:⧸⧸marriott-hiring․com
moet u eerst een vinkje zetten, zogenaand om te bevestigen dat u een mens bent. Daarna verschijnt het beeld dat linksonder te zien is.
De feitelijke BitB-aanval ziet u in het 2e plaatje (meer info onder ALT).
Nb. met een passkey is deze aanval niet mogelijk omdat de domeinnaam niet klopt. Zwakke 2FA (SMS, TOTP of Number Matching) voorkómt *niet* dat u slachtoffer wordt.
#AmazonIsEvil #BigTechIsEvil #LetsEncryptIsEvil #BitB #Phishing #NepWebSites #ATO #AccountTakeOver #AitM #MitM
-
Gisteren en zojuist (13:47) ontving ik phishingmails zogenaamd van KPN.
Ditmaal heb ik screenshots op mijn Windows PC gemaakt, resp. van Thunderbird en Firefox.
De mail zat in mijn inbox (niet als spam herkend): zowel SPF, DKIM als DMARC waren in orde (de reden voor het waarschuwingsteken i.r.t. DKIM is dat er geen DNSSEC gebruikt werd).
De link onderin de mail, onder "Bekijk Status", begint met http:// en dat is raar, want dan heb je geen beveiligde verbinding maar eentje die gekaapt (omgeleid) kan worden (in de praktijk is dat lastig, tenzij u van publieke WiFi gebruikmaakt).
Als ik op die link klik word ik door Firefox gewaarschuwd (rechter plaatje) dat er geen https:// verbinding kon worden opgezet. Gek genoeg beschikt de huidige huurder van de domeinnaam wél over een geldig certificaat voor dat domein (zie https://crt.sh/?id=25632523150 of het DETAILS tabblad van https://www.virustotal.com/gui/domain/doc.cnltd.co.uk/).
LET OP: standaard staat "HTTPS Only" *UIT* in Firefox. Het is zeer verstandig om dit aan te zetten, anders zou u de waarschuwing rechtsonder niet te zien krijgen!
Overigens betekent "HTTPS Only" *niet* dat u geen http meer kunt gebruiken, het enige verschil is dat u nu gewaarschuwd wordt bij http.
Meer info onder ALT.
#Phishing #httpsOnly #https_Only #PublicWiFi #AitM #MitM #EvilTwin
-
@johan : je hebt een punt, maar de hele certificaten-industrie is ziek, webbrowsers zuigen en er bestaat veel te veel misleidende informatie (voorbeeld: zie plaatje met AI-bullshit - zie Alt voor info).
Er bestaan ook Europese certificaatuitgevers - wellicht minder voor DV-certificaten. Echter, met het CA/B-forum (de "toezichthouder" op certificaatuitgevers) bijna volledig in handen van US-organisaties zou Trump ook kunnen opdragen dat browsers alle certificaten van uitgevers in "vijandige" landen niet langer vertrouwen.
De supervisor van organisaties die domeinnamen verhuren is ook grotendeels Amerikaans.
Oftewel, autonomie wensen beperkt zich niet tot certificaten uitgegeven door Google en Let's Encrypt. Ons voorbereiden op worst-case scenario's lijkt mij zeer verstandig.
Overigens heb ik eerder een oplossing voorgesteld voor het phishing-probleem dat ik aankaartte, maar dat is kennelijk off-topic (ik sloeg aan op de kul dat certificaten iets met veilige websites te maken zouden hebben, een leugen die mensen al heel lang op het verkeerde been zet).
@wlaatje @wiert @wendyhk @publicspaces @FTM_nl
#GoogleIsEvil #BigTechIsEvil #USterroristCountry #DigitaleAutonomie #DVcertsAreEvil #CloudflareIsEvil #MitM #AitM #IETF #CABforum #WebBrowsers #Browsers #BeveiligdeWebSite
-
The Silent Breach and the Persistence of Unauthorized Access
938 words, 5 minutes read time.
Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.
Challenging the Failure of Traditional Defensive Postures
When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.
Implementing Rigorous Verification Protocols in a High-Stakes Environment
The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.
Call to Action
The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.
SUPPORTSUBSCRIBECONTACT MED. Bryan King
Sources
- CISA: Business Email Compromise (BEC) Resources
- FBI: Business Email Compromise Information
- FIDO Alliance: Defining Phishing-Resistant Authentication
- Microsoft: Analyzing Adversary-in-the-Middle (AiTM) Techniques
- NIST: Digital Identity Guidelines
- CrowdStrike: Phishing and Social Engineering Analysis
- Palo Alto Networks: Business Email Compromise Explained
- SANS Institute: Protecting Against Advanced Email Threats
- Cybereason: BEC Threat Landscape Report
- Check Point: The Evolution of Phishing
- Proofpoint: Understanding BEC Attacks
- Dark Reading: The Mechanics of Session Hijacking
- ZDNet: The New Era of Targeted Phishing
- Wired: Why Modern Phishing is Succeeding
- Trend Micro: BEC Comprehensive Guide
- Recorded Future: BEC Trend Analysis
- Infosecurity Magazine: FIDO2 and Phishing Resistance
- Varonis: Modern Phishing Techniques Deep Dive
- CSO Online: The Mechanics of BEC
- Fortinet: Cybersecurity Glossary on BEC
- SANS: Analyzing MFA Bypass Tactics
- BleepingComputer: Evolution of Phishing Kits
- Secureworks: BEC Defensive Strategies
- CISA: Mitigating Phishing Campaigns
- Mandiant: Evolving Tactics in BEC
- NIST: Phishing Training Resources
- TechTarget: BEC Definition and Prevention
- Elastic: Detecting Phishing Infrastructure
- Rapid7: The Threat of Session Token Theft
- Cloudflare: Understanding FIDO2 Protocol
Disclaimer:
The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.
Related Posts
Rate this:
#accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust -
@eelcoa : helaas is het allemaal niet zo simpel.
DigiD is beslist niet perfect. En het is absurd als het in handen van een bedrijf, dat aan de VS-wetgeving moet voldoen, valt.
Een niet te onderschatten voordeel van DigiD is dat de server(s) van de partij waar de burger wil inloggen (zoals abp.nl), aan allerlei beveiligingseisen moeten voldoen (en zo'n server met de server(s) van DigiD communiceert).
Als je online authenticatie op (servers van) willekeurige partijen toestaat, zullen AitM (Attacker in the Middle) aanvallen een groot probleem worden (phishing vormt nu al een gigantisch probleem).
Voor betrouwbare authenticatie is het noodzakelijk dat degene die bewijst te zijn wie zij/hij zegt te zijn, de authenticeerder kan vertrouwen. Dat begint ermee dat *jij* weet *wie* de verifieerder is.
In https://tweakers.net/nieuws/204138/nederland-krijgt-een-paspoort-voor-op-internet-hoe-gaat-dat-werken.html#r_18249704 en verder vind je een discussie die ik had met Ivo Jansch (EDIW) en verderop "denan" (IRMA/Yivi). Nb. mijn Tweakers account is afgesloten na ruzie met een vervelende moderator.
Interessant, uit https://yivi.app/privacy_and_security/:
❝
Raak je je telefoon kwijt? Dan kun je in een mum van tijd je Yivi-app blokkeren via Mijn Yivi.
❞
Dat lijkt mij onmogelijk zonder tussenkomst van een centrale server tijdens inloggen.
-
Alternatively, use the NoScript plugin (Firefox on Android and desktop operating systems) and do not trust (default behaviour is to block, explicit blocking is possible too) Cloudflare.
Note that this method does not prevent Cloudflare from knowing your IP-address, but effectively this tells them that they suck if you do not enable their invasive JavaScript code "to detetmine whether the connection is safe".
A connection that is actually very much NOT safe; there's an Attacker in the Middle spying on everything bit exchanged if you continue. They even collect every password you enter on websites proxied by Cloudflare (https://blog.cloudflare.com/password-reuse-rampant-half-user-logins-compromised/).
-
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTMtoken compromise - https://www.redpacketsecurity.com/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitmtoken-compromise/
#threatintel
#aiTM-phishing
#credential-theft
#phishing-attack
#adversary-in-the-middle
#cybersecurity-awareness -
📢⚠️ #Bluekit, a new AI-powered phishing-as-a-service kit, lets attackers bypass MFA using #AiTM attacks and stolen session cookies. With 40+ fake templates and AI tools.
Read: https://hackread.com/bluekit-phishing-kit-targets-platforms-mfa-bypass-attack/
-
@xssfox : no they're not.
IIRC client certs are bound to the TLS channel, while passkeys are bound to the domain name.
Passkeys do not protect against DNS domain takeovers or BGP hijacks (where a malicious website hijacks the domain name and obtains a valid https website certificate).
OTOH if your browser has a TLS connection to a MitM proxy such as Cloudflare or Fastly, you're dead in the water anyway.
-
HERSENLOZE ONLINE LEEFTIJDSVERIFICATIE
Angela von der Leyen in https://nos.nl/artikel/2610545-europese-commissie-wil-strengere-online-leeftijdscontrole-geen-excuses-meer:
"Het is aan ouders om hun kinderen op te voeden."
Rot dan op met je app!
Nooit genoemd bij de nadelen van dit soort junk-apps is het risico op AitM (Attacker in the Middle) aanvallen (mogelijk beperkt tot een klein tijdvenster):
🧔🏻♂️—>📜18+ bewijs📱—>🌐nepsite (of echt en bijverdienen)
🙍🏻♂️💶—>📜18+ bewijs (van🧔🏻♂️)📱—>🌐18+ site
#AitM #MitM #OnlineLeeftijdsVerificatie #OnlineAgeVerification #AgeVerification #LeeftijdsVerificatie #Privacy #DataLekken
-
Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees - https://www.redpacketsecurity.com/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/
#threatintel
#payroll-pirate-attacks
#AiTM
#phishing-resistant-MFA
#Workday
#Canada -
Фишинг 2025–2026: от социальной инженерии к промышленным конвейерам PhaaS
Современный ландшафт киберугроз демонстрирует окончательную трансформацию фишинга из набора разрозненных мошеннических писем в зрелую сервисную индустрию, функционирующую по канонам легитимного ИТ-бизнеса. Фишинг на протяжении многих лет остается одним из наиболее востребованных способов получения первоначального доступа к корпоративной инфраструктуре, сохраняя свою эффективность вопреки массовому внедрению многофакторной аутентификации (MFA) и инвестициям в антиспам-фильтрацию.
https://habr.com/ru/companies/pt/articles/1020880/
#фишинг #mfa #phaas #парсинг #aitm #dkim #dmark #seg #ocr #вредоносное_по
-
@JDGooiker : en zet er alsjeblieft https:// voor, dus zo:
https:⧸⧸gaza.onl
alleen dan niet met ⧸⧸ (unicode) maar met // (twee gewone slashes):
Mastodon heeft de (veilige) link (URL) klikbaar gemaakt.
AANVULLENDE UITLEG
Als www. volgt op https://, wordt ook dat niet getoond. Voorbeeld:https:⧸⧸www.security.nl
Als ik ⧸⧸ vervang door // wordt dat:
Als je gaza.onl direct achter http:// (ipv https://) zet, wordt dat:
http://gaza.onl <= minder veilig, maar de lezer ziet dat niet!
Nogmaals, als je https:// gevolgd door gaza.onl intikt, wordt de link (URL) klikbaar en is deze zo veilig mogelijk:
TECHNISCH
De reden om gepubliceerde URL's (= link's) met https:// te laten beginnen is nogal technisch: URL's zonder protocolaanduiding kunnen door browsers geïnterpreteerd worden als relatief onveilige http:// URL's.Vooral als mensen gebruik maken van public WiFi (trein, restaurant of hotel) kan een http:// verbinding worden gekaapt door een ervaren aanvaller, bij een link die met https:// begint is dat zo goed als onmogelijk.
-
@adamshostack : that may depend on your audience, not everyone will be familiar with swimlanes.
In 2024 I tried to explain "The Chase Case" to Dutch people interested in infosec in https://security.nl/posting/842742 (I can't upload images there and that site is rather unfriendly for mobile browsers, so I try to restrict the width - which is often hard in case of "ASCII art swimlanes").
Note that the Dutch word "stap" means "step" and "Jan" is a very common first name for Dutch men.
English explanation in the Alt text.
Edited to add: the problem at hand is missing channel binding.
-
@Luxano and @adamshostack : this attack also more or less resembles what Terence Eden (@Edent IIRC) described in https://shkspr.mobi/blog/2024/05/bank-scammers-using-genuine-push-notifications-to-trick-their-victims/ : a Man-in-the-Middle attack targeting Chase customers.
And it's interesting to read @briankrebs 's writeup in https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/ - thanks for sharing!
-
And Cloudflare (see Alt text), Fastly and cloud/SaaS providers have access to anything anyway. #NoQuantumComputerNeeded
-
@grammasaurus : if I understand the patent correctly, the content seen by a user in their browser will not for 100% originate from your website given its domain name.
However, Google may let their Chrome browser show your domain name in the address bar and even suggest that a server-authenticated and encrypted valid https connection is being used (proving the authenticity of your website, which is then fully broken).
Google may even force other browser makers (such as Mozilla, sponsored by Google) to do the same.
#Authenticity #Authentic #MitM #AitM #GoogleIsEvil #BigTechIsEvil #TLSisBroken #httpsIsBroken #httpsIsNoLongerE2EE #E2EE
-
Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale - https://www.redpacketsecurity.com/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/