AiTM phishing attacks against Microsoft 365: MFA bypasses, session hijacking, and BEC
ID: f79fa429-9551-5101-b208-dac19d95051b
STIX ID: report--f79fa429-9551-5101-b208-dac19d95051b
Feed Name: ThreatLocker Blog
This report examines Adversary-in-the-Middle (AiTM) phishing against Microsoft 365, where attacker-controlled reverse proxies capture session cookies and tokens after MFA to enable persistent, MFA-bypassing access to Exchange Online, SharePoint, OneDrive, and federated SaaS—fueling mailbox takeover and BEC. It details attack flow, risks from token replay and SSO abuse, and assesses mitigations including Token Binding/CAE, phishing-resistant MFA, sign-in risk policies, aggressive session revocation, and anomalous token reuse detection—highlighting coverage gaps, usability trade-offs, detection delays, and telemetry needs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
