The threat of phishing attacks has significantly increased over the past couple of months. There has been a phishing campaign exploiting AitM techniques to conduct a new and large-scale attack.
Obtaining access to enterprise email accounts by compromising the security protections with the help of these campaigns. Zscaler researchers Sudeep Singh and Jagadeeswar Ramanukolanu affirmed that.
In this attack, the threat actors use the AitM technique to bypass multifactor authentication. In this campaign, Microsoft’s email services are specifically targeted at the end users of enterprise organizations.
A number of prominent targets have been identified, including:-
While all these prime targets are mainly based in the following countries;-
There have been several phishing attacks that have come to light over time, but this would not be the first. Since September 2021, Microsoft announced that a total of over 10,000 organizations have been targeted using AITM techniques.
A background-themed electronic communication will be sent to the targets as part of the ongoing campaign, starting in June 2022. An HTML attachment to this email contains a phishing URL embedded in it, which when clicked on will take you to a phishing page or website.
The phishing page appears to be a Microsoft Office login screen with a Microsoft Office logo on it. The compromised machine must be fingerprinted first before it is possible to determine whether it should be considered the intended target or not.
There are a variety of methods used in this campaign that make it stand out, including:-
Their goal is to load the phishing URL in order to trick the user into clicking on it.
In comparison to traditional phishing attacks, AitM phishing attacks are designed to use a variety of methods in order to obtain the password of unsuspecting users.
Using a phishing kit developed as part of a rogue landing page, a proxy is used to circumvent this. Here, the client and the email server negotiate various terms and conditions in order to be able to communicate with each other.
Additionally, all links to Microsoft domains need to be replaced with equivalent links to phishing domains. During the usage of the fraudulent website, this will ensure that correspondence with the fraudulent website remains intact throughout the usage of the website.
Here below we have mentioned all the common precautionary measures recommended by the security experts at Zscaler:-
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…