MFA Bypass: Circumventing the Security Measure
ID: e7b101a3-7184-56d0-9cc1-53a85493fd1c
STIX ID: report--e7b101a3-7184-56d0-9cc1-53a85493fd1c
Feed Name: ReliaQuest Blog
ReliaQuest describes prevalent MFA bypass techniques—MFA fatigue (push bombing), token theft via infostealer malware and adversary-in-the-middle (AiTM) phishing/proxy attacks, and abuse of MFA-incompatible or misconfigured protocols—and provides actionable hunting indicators (e.g., repeated MFA failures followed by success, reused session IDs across disparate devices, anomalous authentication policies/user agents) plus mitigations (user education, trusted device certificates, shorter token lifetimes, improved logging and MFA choices). The guidance focuses on reducing dwell time by "hunting left," enabling telemetry, and applying defense-in-depth to limit account takeover and subsequent BEC or VPN-based intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
