AITM Attack Targeting Microsoft Email Users
ID: 5bd6f893-e9b1-5530-8243-6ed91724f34d
STIX ID: report--5bd6f893-e9b1-5530-8243-6ed91724f34d
Feed Name: Zscaler Security Research Blog
ThreatLabz documents an active, large-scale AiTM phishing campaign targeting Microsoft email users—primarily enterprise customers across FinTech, Finance, Insurance, Energy and related sectors—where attackers use custom proxy-based kits to bypass MFA, abuse legitimate code-hosting services (CodeSandbox, Glitch) and open-redirectors for redirection, and apply browser fingerprinting and other cloaking techniques; the report details observed domain patterns, unique kit behaviors, post-compromise activity, and non-exhaustive IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
