RECENT reports highlight a critical AiTM phishing campaign targeting healthcare systems, employing account takeovers to hijack Microsoft 365 sessions. Attackers used compromised university accounts to send phishing emails, resulting in over 1,000 emails dispatched in 13 minutes to over 1,454 unique recipients. The operation, utilizing the Sneaky 2FA phishing kit, displayed advanced evasion tactics like spoofing and cloaking techniques on infrastructure.
Organizations are recommended to employ strategies including revoking session tokens, deploying phishing-resistant MFA, and implementing strict application controls to protect against such vulnerabilities.