AiTM attacks and business email compromise attacks: what to watch for
ID: 60b2fb86-41dd-5766-89d0-54fe3896da41
STIX ID: report--60b2fb86-41dd-5766-89d0-54fe3896da41
Feed Name: Expel Blog
This report explains how adversary‑in‑the‑middle (AiTM) credential harvesters are used to bypass MFA and conditional access—commonly enabling business email compromise—by relaying credentials and MFA tokens to authenticate, then using session tokens, registering persistent MFA devices, deleting phishing emails, performing mailbox reconnaissance, and creating inbox rules to hide activity; it also provides specific detections (e.g., consecutive logins from different IPs within ~30 seconds, User registered security info, MoveToDeletedItems/SoftDelete/HardDelete, MailItemsAccessed/AttachmentCollection events, and New/Set‑InboxRule alerts) to help defenders identify and remediate these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
