New Phishing Kits Use Open-Source Tools to Bypass MFA
ID: 3bb30c37-a922-5083-ad3f-220a081564ed
STIX ID: report--3bb30c37-a922-5083-ad3f-220a081564ed
Feed Name: KnowBe4 Blog
Researchers at Lexfo have identified three sophisticated phishing kits built from Evilginx forks that proxy live Microsoft 365 authentication sessions to capture session cookies and OAuth tokens, bypassing multi-factor authentication. The kits incorporate AI-generated personalized lures, multiple delivery formats, and anti-detection features (sender rotation, attachment encryption, HTML-to-image conversion), and are publicly available via GitHub and commercial channels, meaning defenders should assume threat actors of any skill can perform MFA-bypassing AiTM campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
