Tag: adversary in the middle
11 articles

Phishing Kit NovaCookies Exploits Docusign Notifications to Hijack Microsoft 365 Sessions
Meet NovaCookies, a sneaky phishing kit that's being sold for just $320 a month, and can hijack your Microsoft 365 sessions in real-time by cleverly intercepting Docusign notifications. This live adversary-in-the-middle relay captures active sessions, allowing hackers to harvest your credentials and multi-factor authentication codes.

Malicious Chrome Extensions Route Traffic Through Proxies
Hundreds of malicious Chrome extensions have been found to secretly route users' traffic through proxy servers controlled by hackers, allowing them to intercept and spy on sensitive information. This sneaky tactic puts users at risk of having their online activity monitored and exploited.

UNC6671 Targets SaaS Data with Vishing Attacks
Beware of voice phishing scams where attackers pose as IT help desk staff, contacting employees on their personal mobile devices with urgent security migration requests that lead to fake login portals. These clever scams capture sensitive credentials and multi-factor authentication tokens in real-time, putting your SaaS data at risk.

Phishing Service Greatness Exploits RingCentral to Target Microsoft 365 Accounts
A recent security bulletin from RingCentral may have inadvertently given hackers a blueprint for a phishing campaign, as a notorious phishing service known as Greatness has begun targeting Microsoft 365 accounts with sophisticated attacks. Greatness, a phishing-as-a-service platform, has upgraded its tactics to include advanced threats like adversary-in-the-middle attacks and device-code phishing flows.

Greatness PhaaS Expands to Device Code Phishing
Meet Greatness, a phishing-as-a-service powerhouse that's upgraded its game, now offering a one-stop-shop for cybercriminals to mastermind credential theft, device code phishing, and OAuth consent abuse - all from a single, user-friendly dashboard. This commercial crimeware toolkit has evolved into a full-fledged ecosystem, supporting multiple platforms like iCloud, Yahoo, and Google Workspace.

Evilginx Phishing Ops Expose Microsoft 365 MFA Weaknesses
A French security firm stumbled upon a live Microsoft 365 phishing operation when a simple Python command was left exposed in a readable file, revealing a treasure trove of sensitive data. This lucky discovery shed light on the alarming weaknesses in Microsoft 365's multi-factor authentication.

Forg365 Phishing Platform Exploits AI to Target Microsoft 365 Accounts
Meet Forg365, a sneaky new phishing platform that uses AI to make it easy for hackers to target Microsoft 365 accounts and steal sensitive info. This phishing-as-a-service operation offers a range of tools, including AI-generated lures, to help cybercriminals launch convincing attacks.

Bluekit Phishing Kit Enhances Login Theft with Browser-in-the-Middle Tactics
Bluekit's phishing kit just got a sinister upgrade, now using browser-in-the-middle tactics to steal logins in real-time. This move has led to a massive expansion of its infrastructure, with nearly 70 new hostnames appearing in just one week.

Google Exposes BlackFile Extortion Operation's Tactics
Google's Threat Intelligence Group just exposed the clever tactics of the notorious BlackFile extortion operation, revealing how they use voice phishing and sneaky tech tricks to swindle dozens of organizations worldwide. Their clever scheme starts with a simple phone call, where fake IT helpers trick victims into spilling their secrets.

Hackers exploit Google ads for ManageWP phishing scam
Beware of a sneaky phishing scam targeting ManageWP users, where hackers use Google ads to trick victims into divulging their login credentials on a fake website that looks identical to the real one. This clever attack can put hundreds of sites at risk, since each ManageWP account typically hosts multiple sites.

Cybercrime Groups Exploit Vishing, SSO Abuse in SaaS Extortion Spree
Cybercrime groups are launching lightning-fast extortion attacks within trusted SaaS environments, exploiting vishing and SSO abuse to evade detection and strike with precision. By hiding in plain sight, they're creating significant challenges for defenders trying to keep up.