logo

Energy Sector Under Siege: AiTM Phishing Turns Insiders Into Threats

ID: 472b014d-4c72-5133-b5ce-6fd884cfcc95

STIX ID: report--472b014d-4c72-5133-b5ce-6fd884cfcc95

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-23

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft Defender researchers uncovered a sophisticated multi-stage campaign against the energy sector that used Adversary-in-the-Middle (AiTM) phishing to steal session cookies, abused SharePoint to host phishing payloads, and created mailbox rules to delete or mark messages as read for persistence and stealth; compromised accounts were then used to send over 600 targeted phishing emails to contacts and distribution lists while attackers monitored and managed replies to maintain trust.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.