Hackers spoof Microsoft ADFS login pages to steal credentials
ID: bb8ed4ea-2e2a-50da-9395-31a92d5e9cf4
STIX ID: report--bb8ed4ea-2e2a-50da-9395-31a92d5e9cf4
Feed Name: Bleeping Computer
Abnormal Security discovered a targeted help-desk phishing campaign that impersonates corporate IT and presents realistic spoofed ADFS login portals to capture usernames, passwords, and second-factor authentication (including Microsoft Authenticator, Duo, and SMS). Attackers immediately use stolen credentials to access corporate mail, create forwarding rules, perform lateral phishing, and conduct business email compromise; they also use VPN services to obscure their origin. Abnormal recommends migrating to modern authentication solutions (e.g., Microsoft Entra) and improving email filtering and anomaly detection to mitigate these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
