Mail in the Middle – A tool to automate spear phishing campaigns
ID: fa391a57-0fca-5b00-ac51-d22a4a5aae83
STIX ID: report--fa391a57-0fca-5b00-ac51-d22a4a5aae83
Feed Name: SensePost Blog
This report presents a red team technique and tool, Mail-in-the-Middle (Maitm), that leverages typosquatted domains to capture misaddressed “stranded emails,” automate modifications (e.g., tracking pixels, UNC-path injections for NetNTLM exfiltration via CVE-2023-35636, and link/attachment replacement), and forward messages to intended recipients with operational notifications and containerized deployment; it concludes with practical mitigations including lookalike-domain monitoring and takedowns, email impersonation protections, employee data validation on third-party services, and standard anti-phishing controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
