#mimic — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mimic, aggregated by home.social.
-
Passkey-themed social engineering leads to identity and cloud compromise
Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.
Pulse ID: 6aa1c27fd351a18fbe0a8219
Pulse Link: https://otx.alienvault.com/pulse/6aa1c27fd351a18fbe0a8219
Pulse Author: AlienVault
Created: 2026-09-09 20:33:03Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault
-
Passkey-themed social engineering leads to identity and cloud compromise
Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.
Pulse ID: 6aa1c27fd351a18fbe0a8219
Pulse Link: https://otx.alienvault.com/pulse/6aa1c27fd351a18fbe0a8219
Pulse Author: AlienVault
Created: 2026-09-09 20:33:03Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault
-
Passkey-themed social engineering leads to identity and cloud compromise
Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.
Pulse ID: 6aa1c27fd351a18fbe0a8219
Pulse Link: https://otx.alienvault.com/pulse/6aa1c27fd351a18fbe0a8219
Pulse Author: AlienVault
Created: 2026-09-09 20:33:03Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault
-
Passkey-themed social engineering leads to identity and cloud compromise
Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.
Pulse ID: 6aa1c27fd351a18fbe0a8219
Pulse Link: https://otx.alienvault.com/pulse/6aa1c27fd351a18fbe0a8219
Pulse Author: AlienVault
Created: 2026-09-09 20:33:03Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault
-
Passkey-themed social engineering leads to identity and cloud compromise
Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.
Pulse ID: 6aa1c27fd351a18fbe0a8219
Pulse Link: https://otx.alienvault.com/pulse/6aa1c27fd351a18fbe0a8219
Pulse Author: AlienVault
Created: 2026-09-09 20:33:03Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Cloud #CyberSecurity #EDR #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #SocialEngineering #Troll #bot #AlienVault
-
Mamba 2FA: A new contender in the AiTM phishing ecosystem
Mamba 2FA is a newly discovered adversary-in-the-middle (AiTM) phishing kit being sold as phishing-as-a-service (PhaaS). It features capabilities similar to other popular AiTM phishing services, including handling two-step verifications for non-phishing-resistant MFA methods, supporting various authentication systems, and dynamically reflecting organization branding. The kit uses a two-layer infrastructure consisting of link domains and relay servers, leveraging the Socket.IO protocol for communication. Mamba 2FA has been active since at least November 2023 and is commercialized through Telegram. The phishing pages mimic Microsoft 365 services and use sophisticated techniques to evade detection, including HTML attachments with obfuscated content.
Pulse ID: 67043ed32987b7679a2bacd8
Pulse Link: https://otx.alienvault.com/pulse/67043ed32987b7679a2bacd8
Pulse Author: AlienVault
Created: 2024-10-07 20:04:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #AdversaryInTheMiddle #AitM #CyberSecurity #HTML #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #Phishing #Telegram #bot #AlienVault