Multi-Stage AiTM Attack Uses Code Of Conduct Phishing Emails
ID: 72206dd8-7461-5c23-9181-985c61ae9bb4
STIX ID: report--72206dd8-7461-5c23-9181-985c61ae9bb4
Feed Name: Cyber Press
Microsoft Defender Research observed a large-scale credential-theft phishing campaign (April 14–16, 2026) that targeted over 35,000 users across 13,000 organizations—primarily in healthcare and financial sectors—by sending authenticated-looking emails with compliance-themed lures and staging pages that performed an adversary-in-the-middle attack to capture live session tokens and bypass MFA. The report includes evasion tactics (CAPTCHA gating, mobile/desktop behavior changes), defensive recommendations (Zero hour auto purge, SmartScreen, passwordless authentication), and several defanged malicious domains as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
