• Large-Scale AiTM Attack targeting enterprise users of Microsoft email services

    Home » Forums » Cyber Security Information and Advisories » Cyber Security for Business users » Large-Scale AiTM Attack targeting enterprise users of Microsoft email services

    • This topic has 0 replies, 1 voice, and was last updated 10 months ago.
    Author
    Topic
    #2467556

    https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services

    Key points

    Corporate users of Microsoft’s email services are the main targets of this large-scale phishing campaign.

    All these phishing attacks begin with an email sent to the victim with a malicious link.

    The campaign is active at the time of blog publication and new phishing domains are registered almost every day by the threat actor.

    In some cases, the business emails of executives were compromised using this phishing attack and later used to send further phishing emails as part of the same campaign.

    Some of the key industry verticals such as FinTech, Lending, Insurance, Energy and Manufacturing in geographical regions such as the US, UK, New Zealand and Australia are targeted.

    A custom proxy-based phishing kit capable of bypassing multi-factor authentication (MFA) is used in these attacks.

    Various cloaking and browser fingerprinting techniques are leveraged by the threat actor to bypass automated URL analysis systems.

    Numerous URL redirection methods are used to evade corporate email URL analysis solutions.

    Legitimate online code editing services such as CodeSandbox and Glitch are abused to increase the shelf life of the campaign…

    Reply To: Large-Scale AiTM Attack targeting enterprise users of Microsoft email services

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: