logo

Researchers Uncover Multi-Stage AiTM Attack Using SharePoint to Bypass Security Controls

ID: 4c6b8818-eeeb-50c1-833b-2deccf68d131

STIX ID: report--4c6b8818-eeeb-50c1-833b-2deccf68d131

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-24

Date Updated: 2026-04-22

Author: Divya

...
...

Microsoft Defender reported a sophisticated AiTM phishing and BEC campaign targeting energy sector organizations that abused SharePoint file-sharing to bypass email controls, harvest credentials and session cookies, create malicious inbox rules, and send over 600 malicious emails; attackers also registered MFA methods to maintain persistence. Recommended actions include auditing inbox rules, revoking session cookies, reviewing anomalous sign-ins, and applying risk-based conditional access. IOCs listed: 178.130.46.8, 193.36.221.10.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.