Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
ID: 82af39a6-1cac-586d-ac1a-f092fcecc491
STIX ID: report--82af39a6-1cac-586d-ac1a-f092fcecc491
Feed Name: GBHackers
Infoblox Threat Intel researchers detail an active AiTM phishing campaign (since at least May 2026) that uses compromised mailboxes and cloned Microsoft login portals acting as reverse proxies to capture credentials, MFA prompts, and session/OAuth tokens in real time; operators rotate across Phishing-as-a-Service kits (EvilProxy, FlowerStorm/Storm-1167, Kali365), reuse aged domains with injected PHP hosting fake download portals, and have targeted universities, enterprises, and multinational institutions (including EU and UN agencies), enabling persistent tenant access that bypasses standard MFA and conditional access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
