<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Aitm on CuraSec</title><link>https://curasec.metacog.co.kr/tags/aitm/</link><description>Recent content in Aitm on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 07 Aug 2026 11:54:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/aitm/index.xml" rel="self" type="application/rss+xml"/><item><title>Active AitM Phishing Campaign Hijacks M365 Accounts Targeting Finance</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-microsoft-365-aitm-phishing-hijacks-accounts-to-collect-payr/</link><pubDate>Fri, 07 Aug 2026 11:54:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-microsoft-365-aitm-phishing-hijacks-accounts-to-collect-payr/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Active campaign bypasses MFA via session-token theft on M365 — no KEV or PoC signals, but the exposure is real. Prioritize enforcing phishing-resistant MFA (FIDO2/passkeys) for finance and payroll accounts in Entra ID conditional access policies this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Widespread active campaign with clear TTPs: AitM proxy intercept, residential proxy blend-in, and finance-account targeting. Hunt M365 sign-in logs for logins from residential proxy ASNs, and sweep finance/payroll mailboxes for new unauthorized forwarding rules or OAuth app grants added since the campaign was reported.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> An active, widespread BEC-style campaign harvesting payroll and finance email warrants directing the security team to assess phishing-resistant MFA coverage for high-risk financial roles and briefing finance leadership on social-engineering risk this quarter.&lt;/li>
&lt;/ul></description></item><item><title>UNC6671 Vishing-AiTM Campaign Targets Financial Services, Enterprise Cloud</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-unc6671-rebrands-multi-brand-vishing-extortion-targets-finan/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-unc6671-rebrands-multi-brand-vishing-extortion-targets-finan/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Active group uses AiTM to bypass MFA on M365 and Okta; implement phishing-resistant FIDO2/hardware-key MFA and tighten Conditional Access or Okta device-trust policies to invalidate intercepted session tokens.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active campaign with mappable TTPs — hunt for anomalous Okta and M365 session activity (unexpected token origins, bulk SharePoint/OneDrive exfil) since May 2026 and pull the GTIG report for infrastructure IOCs tied to Redact, Pink, Helix, and Falcon brands.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Extortion group is actively hitting financial services, private equity, and professional services — if your org falls in these verticals, brief leadership this week on the campaign and verify that helpdesk impersonation and personal-device contact scenarios are covered in your security awareness program.&lt;/li>
&lt;/ul></description></item><item><title>Insurance phishing evolves to real-time AiTM account hijacking</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-ctm360-research-reveals-how-insurance-phishing-has-evolved-i/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-ctm360-research-reveals-how-insurance-phishing-has-evolved-i/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> AiTM (adversary-in-the-middle) phishing bypasses MFA by proxying sessions in real time; build or tune detections for impossible-travel, session token anomalies, and auth from new ASNs immediately after login events.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Real-time session hijacking erodes MFA as a control — useful context for risk register and security awareness program updates, but no immediate action required given no corroborating signals or named breach.&lt;/li>
&lt;/ul></description></item><item><title>Exposed Server Leaks Three Evilginx M365 Phishing Operations</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-misconfigured-server-reveals-three-evilginx-phishing-operati/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-misconfigured-server-reveals-three-evilginx-phishing-operati/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Evilginx bypasses TOTP-based MFA by proxying credentials; if your M365 tenant uses authenticator-app OTP rather than FIDO2/hardware keys, plan migration to phishing-resistant MFA and enforce Entra ID Conditional Access requiring compliant devices this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Three live AiTM operations were exposed with their full toolkits; pull the IOCs Lexfo published, sweep M365/Entra ID sign-in logs for unfamiliar token-issuing IP ranges, and tune detections for impossible-travel or session-token reuse patterns since AiTM bypasses MFA alerts entirely.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The exposure of three concurrent industrial-scale M365 phishing operations illustrates why TOTP MFA is insufficient as a control; useful context when building the case for phishing-resistant MFA investment in the next budget cycle.&lt;/li>
&lt;/ul></description></item></channel></rss>