Energy Sector Under Siege: AiTM Phishing Turns Insiders Into Threats
ID: 472b014d-4c72-5133-b5ce-6fd884cfcc95
STIX ID: report--472b014d-4c72-5133-b5ce-6fd884cfcc95
Feed Name: securityonline.info
Microsoft Defender researchers uncovered a sophisticated multi-stage campaign against the energy sector that used Adversary-in-the-Middle (AiTM) phishing to steal session cookies, abused SharePoint to host phishing payloads, and created mailbox rules to delete or mark messages as read for persistence and stealth; compromised accounts were then used to send over 600 targeted phishing emails to contacts and distribution lists while attackers monitored and managed replies to maintain trust.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
