logo

AITM Attack Targeting Microsoft Email Users

ID: 5bd6f893-e9b1-5530-8243-6ed91724f34d

STIX ID: report--5bd6f893-e9b1-5530-8243-6ed91724f34d

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

ThreatLabz documents an active, large-scale AiTM phishing campaign targeting Microsoft email users—primarily enterprise customers across FinTech, Finance, Insurance, Energy and related sectors—where attackers use custom proxy-based kits to bypass MFA, abuse legitimate code-hosting services (CodeSandbox, Glitch) and open-redirectors for redirection, and apply browser fingerprinting and other cloaking techniques; the report details observed domain patterns, unique kit behaviors, post-compromise activity, and non-exhaustive IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.