Responding to Adversary in the Middle attacks
With Microsoft disabling basic authentication by default and more organizations using Multi-Factor Authentication (MFA), Adversary-in-the-Middle (AiTM) phishing attacks have seen a rise. While AiTM isn't a new tactic, its frequency is growing as traditional methods of compromising M365 accounts, like simple username and password phishing, become less effective. As MFA becomes more widespread, threat actors are evolving their approaches. We’ve observed this shift in our own Business Email Compromise (BEC) cases, with many of the incidents we investigate nowadays involve AiTM. In this blog, we’ll explore what AiTM is, how to detect it using available logs, how to respond when it’s identified, and most importantly, how to prevent it from occurring in the first place. This blog focuses on incident response. An AiTM attack is a type of phishing where the attacker positions themselves between the victim and a legitimate service to intercept or even manipulate communication. This usually occu
With Microsoft disabling basic authentication by default and more organizations using Multi-Factor Authentication (MFA), Adversary-in-the-Middle (AiTM) phishing attacks have seen a rise. While AiTM isn't a new tactic, its frequency is growing as traditional methods of compromising M365 accounts, like simple username and password phishing, become less effective. As MFA becomes more widespread, threat actors are evolving their approaches. We’ve observed this shift in our own Business Email Compromise (BEC) cases, with many of the incidents we investigate nowadays involve AiTM. In this blog,…
saved by
related reading
- Mamba 2FA: A new contender in the AiTM phishing ecosystem - Sekoia.io Blogblog.sekoia.io
- Threat actors misuse OAuth applications to automate financially driven attacksmicrosoft.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- Exposing and shutting down an inbox heist in actionredcanary.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- Shifting detection left for more effective threat detectionpushsecurity.com
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert networkmicrosoft.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com