logo

AiTM attacks and business email compromise attacks: what to watch for

ID: 60b2fb86-41dd-5766-89d0-54fe3896da41

STIX ID: report--60b2fb86-41dd-5766-89d0-54fe3896da41

Feed Name: Expel Blog

Threat Score
65/100

Date Published: 2023-08-31

Date Updated: 2026-04-27

Author: Brian Badorrek

...
...

This report explains how adversary‑in‑the‑middle (AiTM) credential harvesters are used to bypass MFA and conditional access—commonly enabling business email compromise—by relaying credentials and MFA tokens to authenticate, then using session tokens, registering persistent MFA devices, deleting phishing emails, performing mailbox reconnaissance, and creating inbox rules to hide activity; it also provides specific detections (e.g., consecutive logins from different IPs within ~30 seconds, User registered security info, MoveToDeletedItems/SoftDelete/HardDelete, MailItemsAccessed/AttachmentCollection events, and New/Set‑InboxRule alerts) to help defenders identify and remediate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.