CTAs Using Adversary in the Middle (AiTM) Phishing Attacks
ID: c30447f3-2f28-5b7e-b75c-164883e04149
STIX ID: report--c30447f3-2f28-5b7e-b75c-164883e04149
Feed Name: CISecurity.org Insights Blog
MS-ISAC assesses with moderate confidence that adversaries will continue opportunistic Adversary-in-the-Middle (AiTM) phishing against U.S. State, Local, Tribal, and Territorial (SLTT) entities, enabled by PhaaS and tools such as EvilGinx3, Muraena, Modlishka, and EvilProxy to proxy logins, steal credentials/session cookies, and bypass MFA. Threat actors leverage legitimate services (e.g., Canva) to deliver lures that lead to account takeover, Business Email Compromise, and payroll fraud, and the report recommends defense-in-depth including conditional access, prohibiting self-signed certificates, MS-ISAC’s MDBR, continuous monitoring of sign-ins/inbox rules/MFA changes, DMARC, and external email marking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
