image credit: Adobe Stock

Adversary-in-the-Middle Attack Campaign Hits Dozens of Global Organizations

June 13, 2023

“Dozens” of organizations across the world have been targeted as part of a broad business email compromise (BEC) campaign that involved the use of adversary-in-the-middle (AitM) techniques to carry out the attacks.

“Following a successful phishing attempt, the threat actor gained initial access to one of the victim employee’s account and executed an ‘adversary-in-the-middle’ attack to bypass Office365 authentication and gain persistence access to that account,” Sygnia researchers said in a report shared with The Hacker News.

“Once gaining persistence, the threat actor exfiltrated data from the compromised account and used his access to spread the phishing attacks against other victim’s employees along with several external targeted organizations.”

Read More on The Hacker News