logo

AiTM Phishing Kits Bypass MFA by Hijacking Credentials and Session Tokens

ID: 7f363538-1137-58c6-8907-862e1aa7dc5e

STIX ID: report--7f363538-1137-58c6-8907-862e1aa7dc5e

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2025-04-30

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

Darktrace observed a multi-organization phishing campaign in late 2024–early 2025 abusing Milanote to host credential-harvesting pages and employing the Tycoon 2FA AiTM phishing kit to intercept MFA tokens and session cookies. The campaign enabled attackers to replay sessions, create mailbox rules to conceal activity, and access SaaS accounts from unusual IPs (often via VPNs); Darktrace used anomaly detection and Autonomous Response to disable accounts, reset credentials, and remove malicious rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.