Source |
The Hacker News |
Identifiant |
8618236 |
Date de publication |
2024-11-29 15:36:00 (vue: 2024-11-29 11:07:57) |
Titre |
Phishing-as-a-Service "Rockstar 2FA" Targets Microsoft 365 Users with AiTM Attacks |
Texte |
Cybersecurity researchers are warning about malicious email campaigns leveraging a phishing-as-a-service (PhaaS) toolkit called Rockstar 2FA with an aim to steal Microsoft 365 account credentials.
"This campaign employs an AitM [adversary-in-the-middle] attack, allowing attackers to intercept user credentials and session cookies, which means that even users with multi-factor authentication (MFA)
Cybersecurity researchers are warning about malicious email campaigns leveraging a phishing-as-a-service (PhaaS) toolkit called Rockstar 2FA with an aim to steal Microsoft 365 account credentials.
"This campaign employs an AitM [adversary-in-the-middle] attack, allowing attackers to intercept user credentials and session cookies, which means that even users with multi-factor authentication (MFA) |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
2fa 365 about account adversary aim aitm allowing are attack attackers attacks authentication called campaign campaigns cookies credentials cybersecurity email employs even factor intercept leveraging malicious means mfa microsoft middle multi phaas phishing researchers rockstar service session steal targets toolkit user users warning which |
Tags |
|
Stories |
|
Move |
|