logo

Hijacker helper VoidProxy boosts Google, Microsoft accounts on demand

ID: fcfa3a4d-69a7-57c6-be2a-9bcd2e4cde7c

STIX ID: report--fcfa3a4d-69a7-57c6-be2a-9bcd2e4cde7c

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-09-11

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Okta Threat Intelligence uncovered an active phishing-as-a-service operation named VoidProxy that uses compromised marketing senders, shortened links, Cloudflare-protected phishing pages and an AiTM proxy to capture credentials, MFA responses, and session cookies from Google and Microsoft sign-ins in real time; stolen session cookies are exfiltrated to attacker dashboards and sold to criminal customers, enabling account takeover across multiple industries and geographies, with Okta recommending phishing-resistant authenticators (FIDO2/passkeys/Okta FastPass) as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.