tag: Aitm · 4 items
- Engineer — Plan: Active campaign bypasses MFA via session-token theft on M365 — no KEV or PoC signals, but the exposure is real. Prioritize enforcing phishing-resistant MFA (FIDO2/passkeys) for finance and payroll accounts in Entra ID conditional access policies this quarter.
- SOC/IR — Act: Widespread active campaign with clear TTPs: AitM proxy intercept, residential proxy blend-in, and finance-account targeting. Hunt M365 sign-in logs for logins from residential proxy ASNs, and sweep finance/payroll mailboxes for new unauthorized forwarding rules or OAuth app grants added since the campaign was reported.
- Leader — Plan: An active, widespread BEC-style campaign harvesting payroll and finance email warrants directing the security team to assess phishing-resistant MFA coverage for high-risk financial roles and briefing finance leadership on social-engineering risk this quarter.
- Engineer — Plan: Active group uses AiTM to bypass MFA on M365 and Okta; implement phishing-resistant FIDO2/hardware-key MFA and tighten Conditional Access or Okta device-trust policies to invalidate intercepted session tokens.
- SOC/IR — Act: Active campaign with mappable TTPs — hunt for anomalous Okta and M365 session activity (unexpected token origins, bulk SharePoint/OneDrive exfil) since May 2026 and pull the GTIG report for infrastructure IOCs tied to Redact, Pink, Helix, and Falcon brands.
- Leader — Act: Extortion group is actively hitting financial services, private equity, and professional services — if your org falls in these verticals, brief leadership this week on the campaign and verify that helpdesk impersonation and personal-device contact scenarios are covered in your security awareness program.
- Engineer — Skip
- SOC/IR — Plan: AiTM (adversary-in-the-middle) phishing bypasses MFA by proxying sessions in real time; build or tune detections for impossible-travel, session token anomalies, and auth from new ASNs immediately after login events.
- Leader — Learn: Real-time session hijacking erodes MFA as a control — useful context for risk register and security awareness program updates, but no immediate action required given no corroborating signals or named breach.
- Engineer — Plan: Evilginx bypasses TOTP-based MFA by proxying credentials; if your M365 tenant uses authenticator-app OTP rather than FIDO2/hardware keys, plan migration to phishing-resistant MFA and enforce Entra ID Conditional Access requiring compliant devices this quarter.
- SOC/IR — Act: Three live AiTM operations were exposed with their full toolkits; pull the IOCs Lexfo published, sweep M365/Entra ID sign-in logs for unfamiliar token-issuing IP ranges, and tune detections for impossible-travel or session-token reuse patterns since AiTM bypasses MFA alerts entirely.
- Leader — Learn: The exposure of three concurrent industrial-scale M365 phishing operations illustrates why TOTP MFA is insufficient as a control; useful context when building the case for phishing-resistant MFA investment in the next budget cycle.