New AiTM Attack Campaign That Bypasses MFA Targeting Microsoft 365 and Okta Users
ID: 8832c11f-fe05-5c48-ae4b-a314e9144036
STIX ID: report--8832c11f-fe05-5c48-ae4b-a314e9144036
Feed Name: cybersecurityNews.com
Datadog and other analysts observed an active, sophisticated phishing campaign (AITM) targeting Microsoft 365 and Okta SSO that proxies legitimate authentication flows, injects JavaScript to harvest usernames and session cookies, and uses those stolen session tokens to access accounts without defeating MFA. The campaign uses lookalike Okta domains, shortened links via compromised Salesforce Marketing Cloud mailboxes, Cloudflare-hosted first-stage domains, and a second-stage Okta proxy to transparently capture and replay sessions across multiple companies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
