AiTM Phishing Kits Bypass MFA by Hijacking Credentials and Session Tokens
ID: 7f363538-1137-58c6-8907-862e1aa7dc5e
STIX ID: report--7f363538-1137-58c6-8907-862e1aa7dc5e
Feed Name: GBHackers
Darktrace observed a multi-organization phishing campaign in late 2024–early 2025 abusing Milanote to host credential-harvesting pages and employing the Tycoon 2FA AiTM phishing kit to intercept MFA tokens and session cookies. The campaign enabled attackers to replay sessions, create mailbox rules to conceal activity, and access SaaS accounts from unusual IPs (often via VPNs); Darktrace used anomaly detection and Autonomous Response to disable accounts, reset credentials, and remove malicious rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
