Microsoft Disclosed A Large Scale Phishing Campaign Against 10 000 Organizations Using Office 365
Microsoft disclosed on Tuesday a large-scale phishing campaign even on accounts secured with multi-factor authentication (MFA) targeting over 10,000 organizations by hijacking Office 365’s authentication process since 2021. Microsoft’s cyber security team reported that the attacker stole credentials and session cookies to gain access to victims’ emails in order to target more with follow-on business email compromise (BEC) campaigns. The security researchers observed that they can use one network to target many by setting up adversary-in-the-middle (AitM) phishing sites which helps the adversary to position itself between two or more networked devices with the support of follow-on behaviors such as Network Sniffing or Transmitted Data Manipulation....