Topic: aitm attacks

  • Office 365 search results hijacked to steal paychecks

    Office 365 search results hijacked to steal paychecks

    A threat actor, Storm-2755, uses search engine poisoning and fake Microsoft login pages to hijack corporate email accounts, primarily targeting Canadian workers. The attack employs an adversary-in-the-middle (AiTM) technique to steal login credentials and session tokens, bypassing multi-factor au...

    Read More »
  • Energy Firms Hit by Sophisticated AiTM Phishing Attacks

    Energy Firms Hit by Sophisticated AiTM Phishing Attacks

    A sophisticated phishing campaign is targeting the energy sector using Adversary-in-the-Middle (AiTM) attacks, which bypass standard email filters and multi-factor authentication (MFA) by stealing login credentials and session cookies. Once an account is compromised, attackers establish persisten...

    Read More »