logo

Intercepting MFA. Phishing and Adversary in The Middle attacks

ID: 5938f1cf-7b77-5c15-82b3-6b13c4724a98

STIX ID: report--5938f1cf-7b77-5c15-82b3-6b13c4724a98

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2023-12-12

Date Updated: 2026-03-24

Author: Adam Harwood

...
...

This report examines Adversary-in-the-Middle (AiTM) phishing used to bypass Microsoft 365 MFA by proxying legitimate sign-ins, capturing session tokens, and pivoting into BEC activity, with observed artifacts in M365 logs (e.g., proxy IPs, atypical user agents, session reuse). It highlights common toolkits such as Evilginx and outlines mitigations including stronger Conditional Access configurations, Microsoft Defender anti-phishing presets, Safe Links/Attachments, URL filtering, password managers, geographic restrictions, and adoption of FIDO2/WebAuthn to achieve verifier impersonation resistance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.