logo

Mail in the Middle – A tool to automate spear phishing campaigns

ID: fa391a57-0fca-5b00-ac51-d22a4a5aae83

STIX ID: report--fa391a57-0fca-5b00-ac51-d22a4a5aae83

Feed Name: SensePost Blog

Date Published: 2024-02-26

Date Updated: 2026-04-30

...
...

This report presents a red team technique and tool, Mail-in-the-Middle (Maitm), that leverages typosquatted domains to capture misaddressed “stranded emails,” automate modifications (e.g., tracking pixels, UNC-path injections for NetNTLM exfiltration via CVE-2023-35636, and link/attachment replacement), and forward messages to intended recipients with operational notifications and containerized deployment; it concludes with practical mitigations including lookalike-domain monitoring and takedowns, email impersonation protections, employee data validation on third-party services, and standard anti-phishing controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.