logo

CTAs Using Adversary in the Middle (AiTM) Phishing Attacks

ID: c30447f3-2f28-5b7e-b75c-164883e04149

STIX ID: report--c30447f3-2f28-5b7e-b75c-164883e04149

Feed Name: CISecurity.org Insights Blog

Date Published: 2024-01-08

Date Updated: 2026-04-19

...
...

MS-ISAC assesses with moderate confidence that adversaries will continue opportunistic Adversary-in-the-Middle (AiTM) phishing against U.S. State, Local, Tribal, and Territorial (SLTT) entities, enabled by PhaaS and tools such as EvilGinx3, Muraena, Modlishka, and EvilProxy to proxy logins, steal credentials/session cookies, and bypass MFA. Threat actors leverage legitimate services (e.g., Canva) to deliver lures that lead to account takeover, Business Email Compromise, and payroll fraud, and the report recommends defense-in-depth including conditional access, prohibiting self-signed certificates, MS-ISAC’s MDBR, continuous monitoring of sign-ins/inbox rules/MFA changes, DMARC, and external email marking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.