Attacker-in-the-middle phishing: how attackers bypass MFA
ID: d50fa5a0-c803-54aa-b062-9001282637cd
STIX ID: report--d50fa5a0-c803-54aa-b062-9001282637cd
Feed Name: Expel Blog
Threat Score
This report documents an attacker-in-the-middle (AitM) credential-phishing incident where attackers proxied a Microsoft 365 login (rnechcollc.com / 137.220.38.57), captured MFA and session cookies to bypass MFA, and retained access for 24 days; the report details detection techniques across cloud, network, and EDR logs and recommends reducing session lifetimes, applying conditional access, and improving phishing defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
