logo

New AiTM Attack Campaign That Bypasses MFA Targeting Microsoft 365 and Okta Users

ID: 8832c11f-fe05-5c48-ae4b-a314e9144036

STIX ID: report--8832c11f-fe05-5c48-ae4b-a314e9144036

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Datadog and other analysts observed an active, sophisticated phishing campaign (AITM) targeting Microsoft 365 and Okta SSO that proxies legitimate authentication flows, injects JavaScript to harvest usernames and session cookies, and uses those stolen session tokens to access accounts without defeating MFA. The campaign uses lookalike Okta domains, shortened links via compromised Salesforce Marketing Cloud mailboxes, Cloudflare-hosted first-stage domains, and a second-stage Okta proxy to transparently capture and replay sessions across multiple companies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.