logo

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

ID: 9561a5bb-057b-531e-bde7-5ab8041d8f90

STIX ID: report--9561a5bb-057b-531e-bde7-5ab8041d8f90

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-26

Date Updated: 2026-07-26

...
...

CTM360 documents a rise in Adversary-in-the-Middle (AiTM) phishing campaigns against insurance and financial portals that proxy victim sessions in real time to capture session tokens and bypass common MFA (SMS, TOTP, email OTP, push). The report details commercial and open-source proxy frameworks (EvilProxy, Evilginx2, custom proxies), why most browser-presentable MFA factors fail, and recommends FIDO2/passkeys, session binding, anomalous session detection, and accelerated migration away from SMS/TOTP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.