logo

Global analysis of Adversary-in-the-Middle phishing threats

ID: 4eeab570-0270-52be-a6d7-2ff9a8281ae7

STIX ID: report--4eeab570-0270-52be-a6d7-2ff9a8281ae7

Feed Name: Sekoia.com

Threat Score
80/100

Date Published: 2025-06-11

Date Updated: 2026-07-20

...
...

This Sekoia TDR report analyzes the rising threat of Adversary-in-the-Middle (AitM) phishing and the Phishing-as-a-Service (PhaaS) ecosystem (e.g., Tycoon 2FA, EvilProxy, NakedPages, Mamba 2FA), describing how reverse-proxy and synchronous relay kits harvest credentials and session cookies to bypass MFA, enabling Business Email Compromise, financial fraud, and espionage; it summarizes common lures, anti-bot and redirection techniques, prevalence of major kits (Jan–Apr 2025), detection/hunting methodologies, and actionable telemetry and IoCs for SOCs and CERTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.