logo

Global analysis of Adversary-in-the-Middle phishing threats

ID: 9f09a162-4ca5-566f-aee3-da2b47042220

STIX ID: report--9f09a162-4ca5-566f-aee3-da2b47042220

Feed Name: Sekoia.io Blog (archive)

Date Published: 2025-06-11

Date Updated: 2026-04-29

Author: Quentin Bourgue, Grégoire Clermont and Sekoia TDR

...
...

This abridged Sekoia TDR report analyzes the accelerating use of Adversary-in-the-Middle (AitM) phishing against Microsoft 365 and Google accounts, driven by a maturing Phishing-as-a-Service ecosystem; it outlines evolving delivery trends (QR to HTML to SVG attachments), layered redirection and anti-bot techniques, and BEC monetization, and presents telemetry-informed monitoring/detection approaches (infrastructure heuristics, Entra ID log analytics) alongside a Q1 2025 ranking of leading AitM kits—led by Tycoon 2FA, Storm-1167, NakedPages, Sneaky 2FA, EvilProxy, and Evilginx—to guide detection, tracking, and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.