Topic: aitm attacks
-
Office 365 search results hijacked to steal paychecks
A threat actor, Storm-2755, uses search engine poisoning and fake Microsoft login pages to hijack corporate email accounts, primarily targeting Canadian workers. The attack employs an adversary-in-the-middle (AiTM) technique to steal login credentials and session tokens, bypassing multi-factor au...
Read More » -
Energy Firms Hit by Sophisticated AiTM Phishing Attacks
A sophisticated phishing campaign is targeting the energy sector using Adversary-in-the-Middle (AiTM) attacks, which bypass standard email filters and multi-factor authentication (MFA) by stealing login credentials and session cookies. Once an account is compromised, attackers establish persisten...
Read More »