Global analysis of Adversary-in-the-Middle phishing threats
ID: 9f09a162-4ca5-566f-aee3-da2b47042220
STIX ID: report--9f09a162-4ca5-566f-aee3-da2b47042220
Feed Name: Sekoia.io Blog (archive)
Date Published: 2025-06-11
Date Updated: 2026-04-29
Author: Quentin Bourgue, Grégoire Clermont and Sekoia TDR
This abridged Sekoia TDR report analyzes the accelerating use of Adversary-in-the-Middle (AitM) phishing against Microsoft 365 and Google accounts, driven by a maturing Phishing-as-a-Service ecosystem; it outlines evolving delivery trends (QR to HTML to SVG attachments), layered redirection and anti-bot techniques, and BEC monetization, and presents telemetry-informed monitoring/detection approaches (infrastructure heuristics, Entra ID log analytics) alongside a Q1 2025 ranking of leading AitM kits—led by Tycoon 2FA, Storm-1167, NakedPages, Sneaky 2FA, EvilProxy, and Evilginx—to guide detection, tracking, and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
