logo

Hackers spoof Microsoft ADFS login pages to steal credentials

ID: bb8ed4ea-2e2a-50da-9395-31a92d5e9cf4

STIX ID: report--bb8ed4ea-2e2a-50da-9395-31a92d5e9cf4

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-02-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Abnormal Security discovered a targeted help-desk phishing campaign that impersonates corporate IT and presents realistic spoofed ADFS login portals to capture usernames, passwords, and second-factor authentication (including Microsoft Authenticator, Duo, and SMS). Attackers immediately use stolen credentials to access corporate mail, create forwarding rules, perform lateral phishing, and conduct business email compromise; they also use VPN services to obscure their origin. Abnormal recommends migrating to modern authentication solutions (e.g., Microsoft Entra) and improving email filtering and anomaly detection to mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.