Code of Conduct Phish Hits 35,000 Users in Multi-Stage AiTM Attack
ID: b07ba772-0984-572e-bbd1-9a04f91e6458
STIX ID: report--b07ba772-0984-572e-bbd1-9a04f91e6458
Feed Name: GBHackers
Threat Score
A sophisticated, large-scale phishing campaign used internal code-of-conduct lures, PDF attachments, Cloudflare CAPTCHAs, and an AiTM Microsoft sign-in flow to harvest session tokens and bypass MFA, impacting ~35,000 users across 13,000 organizations (primarily U.S.) and targeting healthcare, financial services, professional services, and technology sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
