
Hackers Use Procurement Phishing and AiTM Kits to Hijack MFA-Protected Microsoft 365 Sessions
A sophisticated phishing campaign is using procurement-themed emails and adversary-in-the-middle (AiTM) kits to steal MFA-protected Microsoft 365 sessions. Rather than breaking MFA, attackers proxy legitimate sign-in flows and capture the session cookies and tokens created after victims authenticate. The campaign reportedly targets enterprises, universities, multinational organizations, and public-sector entities through RFIs, bid invitations, and project-document […]
The post Hackers Use Procurement Phishing and AiTM Kits to Hijack MFA-Protected Microsoft 365 Sessions appeared first on Cyber Security News.