Responding to Adversary in the Middle attacks
With Microsoft disabling basic authentication by default and more organizations using Multi-Factor Authentication (MFA), Adversary-in-the-Middle (AiTM) phishing attacks have seen a rise. While AiTM isn't a new tactic, its frequency is growing as traditional methods of compromising M365 accounts, like simple username and password phishing, become less effective. As MFA becomes more widespread, threat actors are evolving their approaches. We’ve observed this shift in our own Business Email Compromise (BEC) cases, with many of the incidents we investigate nowadays involve AiTM. In this blog, we’ll explore what AiTM is, how to detect it using available logs, how to respond when it’s identified, and most importantly, how to prevent it from occurring in the first place. This blog focuses on incident response. An AiTM attack is a type of phishing where the attacker positions themselves between the victim and a legitimate service to intercept or even manipulate communication. This usually occu
Explore this link on the map →