Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack
ID: 2af2bef4-c1b9-5c9e-b658-14f10c2b3df6
STIX ID: report--2af2bef4-c1b9-5c9e-b658-14f10c2b3df6
Feed Name: Bleeping Computer
A report on PoisonSeed details a phishing campaign that uses adversary-in-the-middle pages to harvest credentials and trigger WebAuthn cross-device authentication (QR code/Bluetooth) in an effort to downgrade FIDO2 protections and trick users into approving attacker-initiated logins; however, Expel later clarified that in the observed case the proximity requirement caused MFA to fail and no access was obtained. The piece highlights the TTPs involved and advises mitigations such as geo-based access controls, monitoring for anomalous FIDO key registrations, and enforcing Bluetooth-based proximity for cross-device authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
