Hijacker helper VoidProxy boosts Google, Microsoft accounts on demand
ID: fcfa3a4d-69a7-57c6-be2a-9bcd2e4cde7c
STIX ID: report--fcfa3a4d-69a7-57c6-be2a-9bcd2e4cde7c
Feed Name: The Register (Security)
Okta Threat Intelligence uncovered an active phishing-as-a-service operation named VoidProxy that uses compromised marketing senders, shortened links, Cloudflare-protected phishing pages and an AiTM proxy to capture credentials, MFA responses, and session cookies from Google and Microsoft sign-ins in real time; stolen session cookies are exfiltrated to attacker dashboards and sold to criminal customers, enabling account takeover across multiple industries and geographies, with Okta recommending phishing-resistant authenticators (FIDO2/passkeys/Okta FastPass) as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
