home.social

#aitm — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #aitm, aggregated by home.social.

fetched live
  1. Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

    Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.

    Pulse ID: 6a84c514863d37cbadb72833
    Pulse Link: otx.alienvault.com/pulse/6a84c
    Pulse Author: AlienVault
    Created: 2026-08-18 20:48:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #AdversaryInTheMiddle #AitM #Browser #Cookies #CyberSecurity #Education #Email #HTML #InfoSec #Java #JavaScript #Manufacturing #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #Rust #SVG #Word #bot #AlienVault

  2. Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails

    Indicators extracted from public reporting. Source: arcticwolf.com/resources/blog/

    Pulse ID: 6a79a0380064469905c39916
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 09:56:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #CyberHunter_NL

  3. UNC6671 non è mai morta: dietro Redact, Pink, Helix e Falcon c’è sempre BlackFile

    Google Threat Intelligence Group svela come il gruppo di estorsione UNC6671, dato per chiuso a maggio con il ritiro del brand BlackFile, sia in realtà proseguito sotto quattro nuove insegne. Vishing mirato, phishing AiTM e furto di dati SaaS colpiscono private equity, hedge fund e big della finanza globale.

    insicurezzadigitale.com/unc667

  4. Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

    Indicators extracted from public reporting. Source: arcticwolf.com/resources/blog/

    Pulse ID: 6a75ba1ded6ccee05f831c5d
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 10:57:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #CyberHunter_NL

  5. Payroll Pirates: Strange New Tides in Business Email Compromise

    Arctic Wolf is tracking an active, widespread phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle (AiTM) techniques. The operation employs voicemail-themed phishing emails that redirect victims through multiple legitimate services to AiTM proxy infrastructure, which intercepts authentication sessions even when multi-factor authentication is enabled. Once compromised, threat actors use residential proxies to maintain access, conducting automated sign-ins at eight-hour intervals while collecting email from personnel involved in financial workflows. The campaign uses Microsoft Graph for reconnaissance targeting payroll, HR, and finance users, followed by coordinated mailbox collection. Activity affects organizations across healthcare, education, manufacturing, government, and professional services sectors in the United States, Canada, and Europe. The campaign shares characteristics with Microsoft-tracked Storm-2755 activity cluster.

    Pulse ID: 6a7546d2694489fe6ddddcd5
    Pulse Link: otx.alienvault.com/pulse/6a754
    Pulse Author: AlienVault
    Created: 2026-08-07 02:45:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #Canada #CyberSecurity #Education #Email #Europe #Government #Healthcare #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RCE #UnitedStates #bot #AlienVault

  6. Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts

    Indicators extracted from public reporting. Source: zerobec.com/blog/greatness-pha

    Pulse ID: 6a734f29adb20c14f4081778
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 14:56:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  7. Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

    Indicators extracted from public reporting. Source: zerobec.com/blog/greatness-pha

    Pulse ID: 6a7227e3d5fa0bf81d2044b3
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: CyberHunter_NL
    Created: 2026-08-04 17:56:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AitM #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  8. We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages.
    The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties.
    What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands.
    ⛔ usersatisfactionlab[.]de
    ⛔ assessmentevaluationreport[.]com
    ⛔ duemineral[.]uk
    infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga

  9. Operation Olympus Blade: BKA e FBI smantellano Kratos, il phishing-as-a-service da 1.800 clienti in 35 paesi

    Le autorità tedesche e statunitensi hanno sequestrato oltre 200 server e arrestato in Indonesia lo sviluppatore di Kratos, piattaforma PhaaS con tecniche AiTM usata da 1.800 clienti per 15.000 campagne di phishing al mese contro account Microsoft 365.

    insicurezzadigitale.com/operat

  10. Waarschuwing voor "Browser in the Browser" aanvallen

    Bij een BitB-aanval toont een nepwebsite een nep pop-up-venster dat eruit ziet als een (deels of geheel) nieuw browser-venster. Gesuggereerd wordt dat u uw inloggegevens moet invoeren op bijvoorbeeld:

    https:⧸⧸accounts.google.com/signin/v3/

    maar dat is allemaal fake: door u ingevoerde nloggegevens vallen zo in handen van de eigenaar van de onderliggende website, die daarmee als u kan inloggen en uw account kan kapen.

    Mijn bron: bleepingcomputer.com/news/secu

    Onderin gist.github.com/BushidoUK/57c3 ziet u een lijst van criminele domeinnamen waar deze techniek op werd of nog wordt toegepast.

    De hieronder getoonde website is gehost bij Amazon (zie het RELATIONS tabblad van virustotal.com/gui/domain/marr). Als u zou openen (dat raad ik af):

    https:⧸⧸marriott-hiring․com

    moet u eerst een vinkje zetten, zogenaand om te bevestigen dat u een mens bent. Daarna verschijnt het beeld dat linksonder te zien is.

    De feitelijke BitB-aanval ziet u in het 2e plaatje (meer info onder ALT).

    Nb. met een passkey is deze aanval niet mogelijk omdat de domeinnaam niet klopt. Zwakke 2FA (SMS, TOTP of Number Matching) voorkómt *niet* dat u slachtoffer wordt.

    #AmazonIsEvil #BigTechIsEvil #LetsEncryptIsEvil #BitB #Phishing #NepWebSites #ATO #AccountTakeOver #AitM #MitM

  11. Gisteren en zojuist (13:47) ontving ik phishingmails zogenaamd van KPN.

    Ditmaal heb ik screenshots op mijn Windows PC gemaakt, resp. van Thunderbird en Firefox.

    De mail zat in mijn inbox (niet als spam herkend): zowel SPF, DKIM als DMARC waren in orde (de reden voor het waarschuwingsteken i.r.t. DKIM is dat er geen DNSSEC gebruikt werd).

    De link onderin de mail, onder "Bekijk Status", begint met http:// en dat is raar, want dan heb je geen beveiligde verbinding maar eentje die gekaapt (omgeleid) kan worden (in de praktijk is dat lastig, tenzij u van publieke WiFi gebruikmaakt).

    Als ik op die link klik word ik door Firefox gewaarschuwd (rechter plaatje) dat er geen https:// verbinding kon worden opgezet. Gek genoeg beschikt de huidige huurder van de domeinnaam wél over een geldig certificaat voor dat domein (zie crt.sh/?id=25632523150 of het DETAILS tabblad van virustotal.com/gui/domain/doc.).

    LET OP: standaard staat "HTTPS Only" *UIT* in Firefox. Het is zeer verstandig om dit aan te zetten, anders zou u de waarschuwing rechtsonder niet te zien krijgen!

    Overigens betekent "HTTPS Only" *niet* dat u geen http meer kunt gebruiken, het enige verschil is dat u nu gewaarschuwd wordt bij http.

    Meer info onder ALT.

    #Phishing #httpsOnly #https_Only #PublicWiFi #AitM #MitM #EvilTwin

  12. @johan : je hebt een punt, maar de hele certificaten-industrie is ziek, webbrowsers zuigen en er bestaat veel te veel misleidende informatie (voorbeeld: zie plaatje met AI-bullshit - zie Alt voor info).

    Er bestaan ook Europese certificaatuitgevers - wellicht minder voor DV-certificaten. Echter, met het CA/B-forum (de "toezichthouder" op certificaatuitgevers) bijna volledig in handen van US-organisaties zou Trump ook kunnen opdragen dat browsers alle certificaten van uitgevers in "vijandige" landen niet langer vertrouwen.

    De supervisor van organisaties die domeinnamen verhuren is ook grotendeels Amerikaans.

    Oftewel, autonomie wensen beperkt zich niet tot certificaten uitgegeven door Google en Let's Encrypt. Ons voorbereiden op worst-case scenario's lijkt mij zeer verstandig.

    Overigens heb ik eerder een oplossing voorgesteld voor het phishing-probleem dat ik aankaartte, maar dat is kennelijk off-topic (ik sloeg aan op de kul dat certificaten iets met veilige websites te maken zouden hebben, een leugen die mensen al heel lang op het verkeerde been zet).

    @wlaatje @wiert @wendyhk @publicspaces @FTM_nl

    #GoogleIsEvil #BigTechIsEvil #USterroristCountry #DigitaleAutonomie #DVcertsAreEvil #CloudflareIsEvil #MitM #AitM #IETF #CABforum #WebBrowsers #Browsers #BeveiligdeWebSite

  13. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  14. @eelcoa : helaas is het allemaal niet zo simpel.

    DigiD is beslist niet perfect. En het is absurd als het in handen van een bedrijf, dat aan de VS-wetgeving moet voldoen, valt.

    Een niet te onderschatten voordeel van DigiD is dat de server(s) van de partij waar de burger wil inloggen (zoals abp.nl), aan allerlei beveiligingseisen moeten voldoen (en zo'n server met de server(s) van DigiD communiceert).

    Als je online authenticatie op (servers van) willekeurige partijen toestaat, zullen AitM (Attacker in the Middle) aanvallen een groot probleem worden (phishing vormt nu al een gigantisch probleem).

    Voor betrouwbare authenticatie is het noodzakelijk dat degene die bewijst te zijn wie zij/hij zegt te zijn, de authenticeerder kan vertrouwen. Dat begint ermee dat *jij* weet *wie* de verifieerder is.

    In tweakers.net/nieuws/204138/ned en verder vind je een discussie die ik had met Ivo Jansch (EDIW) en verderop "denan" (IRMA/Yivi). Nb. mijn Tweakers account is afgesloten na ruzie met een vervelende moderator.

    Interessant, uit yivi.app/privacy_and_security/:

    Raak je je telefoon kwijt? Dan kun je in een mum van tijd je Yivi-app blokkeren via Mijn Yivi.

    Dat lijkt mij onmogelijk zonder tussenkomst van een centrale server tijdens inloggen.

    #Yivi #EDIW #EUDIW #AitM #MitM #OnlineAuthenticatie

  15. @SpaceLifeForm @thomasfuchs

    Alternatively, use the NoScript plugin (Firefox on Android and desktop operating systems) and do not trust (default behaviour is to block, explicit blocking is possible too) Cloudflare.

    Note that this method does not prevent Cloudflare from knowing your IP-address, but effectively this tells them that they suck if you do not enable their invasive JavaScript code "to detetmine whether the connection is safe".

    A connection that is actually very much NOT safe; there's an Attacker in the Middle spying on everything bit exchanged if you continue. They even collect every password you enter on websites proxied by Cloudflare (blog.cloudflare.com/password-r).

    #CloudflareIsEvil #BigTechIsEvil #AitM #MitM #Cloudflare

  16. 📢⚠️ #Bluekit, a new AI-powered phishing-as-a-service kit, lets attackers bypass MFA using #AiTM attacks and stolen session cookies. With 40+ fake templates and AI tools.

    Read: hackread.com/bluekit-phishing-

    #Cybersecurity #Phishing #MFA #AI #Hacking #PhaaS

  17. @xssfox : no they're not.

    IIRC client certs are bound to the TLS channel, while passkeys are bound to the domain name.

    Passkeys do not protect against DNS domain takeovers or BGP hijacks (where a malicious website hijacks the domain name and obtains a valid https website certificate).

    OTOH if your browser has a TLS connection to a MitM proxy such as Cloudflare or Fastly, you're dead in the water anyway.

    #TLS #MitM #AitM #Passkeys

  18. HERSENLOZE ONLINE LEEFTIJDSVERIFICATIE

    Angela von der Leyen in nos.nl/artikel/2610545-europes:

    "Het is aan ouders om hun kinderen op te voeden."

    Rot dan op met je app!

    Nooit genoemd bij de nadelen van dit soort junk-apps is het risico op AitM (Attacker in the Middle) aanvallen (mogelijk beperkt tot een klein tijdvenster):

    🧔🏻‍♂️—>📜18+ bewijs📱—>🌐nepsite (of echt en bijverdienen)

    🙍🏻‍♂️💶—>📜18+ bewijs (van🧔🏻‍♂️)📱—>🌐18+ site

    #AitM #MitM #OnlineLeeftijdsVerificatie #OnlineAgeVerification #AgeVerification #LeeftijdsVerificatie #Privacy #DataLekken

  19. Фишинг 2025–2026: от социальной инженерии к промышленным конвейерам PhaaS

    Современный ландшафт киберугроз демонстрирует окончательную трансформацию фишинга из набора разрозненных мошеннических писем в зрелую сервисную индустрию, функционирующую по канонам легитимного ИТ-бизнеса. Фишинг на протяжении многих лет остается одним из наиболее востребованных способов получения первоначального доступа к корпоративной инфраструктуре, сохраняя свою эффективность вопреки массовому внедрению многофакторной аутентификации (MFA) и инвестициям в антиспам-фильтрацию.

    habr.com/ru/companies/pt/artic

    #фишинг #mfa #phaas #парсинг #aitm #dkim #dmark #seg #ocr #вредоносное_по

  20. @JDGooiker : en zet er alsjeblieft https:// voor, dus zo:

    https:⧸⧸gaza.onl

    alleen dan niet met ⧸⧸ (unicode) maar met // (twee gewone slashes):

    gaza.onl

    Mastodon heeft de (veilige) link (URL) klikbaar gemaakt.

    AANVULLENDE UITLEG
    Als www. volgt op https://, wordt ook dat niet getoond. Voorbeeld:

    https:⧸⧸www.security.nl

    Als ik ⧸⧸ vervang door // wordt dat:

    security.nl

    Als je gaza.onl direct achter http:// (ipv https://) zet, wordt dat:

    gaza.onl <= minder veilig, maar de lezer ziet dat niet!

    Nogmaals, als je https:// gevolgd door gaza.onl intikt, wordt de link (URL) klikbaar en is deze zo veilig mogelijk:

    gaza.onl

    TECHNISCH
    De reden om gepubliceerde URL's (= link's) met https:// te laten beginnen is nogal technisch: URL's zonder protocolaanduiding kunnen door browsers geïnterpreteerd worden als relatief onveilige http:// URL's.

    Vooral als mensen gebruik maken van public WiFi (trein, restaurant of hotel) kan een http:// verbinding worden gekaapt door een ervaren aanvaller, bij een link die met https:// begint is dat zo goed als onmogelijk.

    @michielminded

    #httpsVersusHttp #MitM #AitM

  21. @adamshostack : that may depend on your audience, not everyone will be familiar with swimlanes.

    In 2024 I tried to explain "The Chase Case" to Dutch people interested in infosec in security.nl/posting/842742 (I can't upload images there and that site is rather unfriendly for mobile browsers, so I try to restrict the width - which is often hard in case of "ASCII art swimlanes").

    Note that the Dutch word "stap" means "step" and "Jan" is a very common first name for Dutch men.

    English explanation in the Alt text.

    Edited to add: the problem at hand is missing channel binding.

    @Luxano @Edent @briankrebs

    #MitM #AitM #Chase

  22. 📰 Sophisticated AiTM Phishing Campaign Targets TikTok for Business Accounts to Bypass MFA

    ⚠️ Phishing Alert: Sophisticated AiTM campaign targeting TikTok for Business accounts to bypass MFA and steal session cookies. Attackers use Google Storage URLs to evade detection. #Phishing #AiTM #TikTok

    🔗 cyber.netsecops.io/articles/ph

  23. @grammasaurus : if I understand the patent correctly, the content seen by a user in their browser will not for 100% originate from your website given its domain name.

    However, Google may let their Chrome browser show your domain name in the address bar and even suggest that a server-authenticated and encrypted valid https connection is being used (proving the authenticity of your website, which is then fully broken).

    Google may even force other browser makers (such as Mozilla, sponsored by Google) to do the same.

    @SteveRudolfi

    #Authenticity #Authentic #MitM #AitM #GoogleIsEvil #BigTechIsEvil #TLSisBroken #httpsIsBroken #httpsIsNoLongerE2EE #E2EE