home.social

#mimic — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mimic, aggregated by home.social.

  1. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  2. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  3. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  4. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  5. Passkey-themed social engineering leads to identity and cloud compromise

    Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

    Pulse ID: 6aa1c27fd351a18fbe0a8219
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:33:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault

  6. Mamba 2FA: A new contender in the AiTM phishing ecosystem

    Mamba 2FA is a newly discovered adversary-in-the-middle (AiTM) phishing kit being sold as phishing-as-a-service (PhaaS). It features capabilities similar to other popular AiTM phishing services, including handling two-step verifications for non-phishing-resistant MFA methods, supporting various authentication systems, and dynamically reflecting organization branding. The kit uses a two-layer infrastructure consisting of link domains and relay servers, leveraging the Socket.IO protocol for communication. Mamba 2FA has been active since at least November 2023 and is commercialized through Telegram. The phishing pages mimic Microsoft 365 services and use sophisticated techniques to evade detection, including HTML attachments with obfuscated content.

    Pulse ID: 67043ed32987b7679a2bacd8
    Pulse Link: otx.alienvault.com/pulse/67043
    Pulse Author: AlienVault
    Created: 2024-10-07 20:04:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #AdversaryInTheMiddle #AitM #CyberSecurity #HTML #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #Telegram #bot #AlienVault