#AiTM
November 21, 2024 at 2:17 PM
Sekoia says it discovered a new AitM phishing kit named Sneaky 2FA that was designed for targeting Microsoft 365 accounts

blog.sekoia.io/sneaky-2fa-e...
Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
In this blog post, learn about Sneaky 2FA, a new Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts.
blog.sekoia.io
January 18, 2025 at 11:14 PM
𝚌𝚎𝚊𝚜𝚎𝚕𝚎𝚜𝚜 𝚊𝚍𝚜 𝚊𝚗𝚍
𝚞𝚗𝚏𝚘𝚛𝚝𝚞𝚗𝚊𝚝𝚎 𝚛𝚎𝚏𝚛𝚊𝚒𝚗𝚜—
Implant AIᵀᴹ

. . . ✩°。𓋼𓏲⋆.❨𖦹₊˚୭ . . .

#ScifaikuSaturday #prompt | #implant
#scifi #haiku
#GrimScribe | unfortunate refrain
May 16, 2026 at 1:58 AM
Acho que aquele tracking não estava tão errado no fim, isso é claramente desespero (e crime, uma nojeira sem fim, etc), vamos ver o que vem aíTM
A gravidade disso aqui:

Governador acusando adversário político ENQUANTO A VOTAÇÃO ESTÁ OCORRENDO
October 27, 2024 at 5:46 PM
Russian espionage group APT28 compromised MikroTik and TP-Link routers to redirect traffic for certain authentication operations to AitM phishing kits

This botnet was taken down today by the FBI, DOJ, Lumen, and Microsoft

www.lumen.com/blog-and-new...
April 7, 2026 at 4:10 PM
Microsoft reports a rise of 146% in AitM phishing over the past year

techcommunity.microsoft.com/blog/identit...
December 8, 2024 at 3:23 PM
A new phishing-as-a-service (PhaaS) platform named 'Rockstar 2FA' has emerged, facilitating large-scale adversary-in-the-middle (AiTM) attacks to steal Microsoft 365 credentials.

www.bleepingcomputer.com/news/securit...
New Rockstar 2FA phishing service targets Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) platform named 'Rockstar 2FA' has emerged, facilitating large-scale adversary-in-the-middle (AiTM) attacks to steal Microsoft 365 credentials.
www.bleepingcomputer.com
December 1, 2024 at 2:00 AM
Sekoia has published a report looking at the AitM phishing kit landscape, its evolution, and today's largest providers.

blog.sekoia.io/global-analy...
June 12, 2025 at 12:23 AM
📝 Our latest #TDR report delivers an in-depth analysis of Adversary-in-the-Middle (#AitM) #phishing threats - targeting Microsoft 365 and Google accounts - and their ecosystem.

This report shares actionable intelligence to help analysts detect and investigate AitM phishing.
June 11, 2025 at 8:32 AM
Device code phishing is exploding, and AiTM actors are getting in on it.

We found ODx phishing-as-a-service providing device code capabilities in addition to their AiTM offerings. ODx is one of the most popular AiTM kits currently. It's also tracked as Storm-1167 and FlowerStorm.
May 4, 2026 at 8:56 PM
Excellent question 😁

AitM doesn't have our PRT, so it asks for user/pass and now CA knows which policies apply

If a policy requires hybrid or compliant device, AitM is told to do device auth, but it can't and is blocked

It can't ask our device to do it because cert based auth is awesome like that
How does the require compliant device CA policy stop the typical
session cookie theft attack? You are required the PRT in addition to the cookie?
January 25, 2025 at 8:57 PM
Attackers redirecting direct deposits by harvest victims credentials and MFA codes using an adversary-in-the-middle (AitM) phishing link, thereby gaining access to their Exchange Online accounts and taking over Workday profiles through single sign-on (SSO).

thehackernews.com/2025/10/micr...
October 10, 2025 at 5:39 PM
🔍 TDR analysts discovered a new Adversary-in-the-Middle (#AiTM) #phishing kit, specifically targeting Microsoft 365 accounts and circumventing 2-step verification: Sneaky 2FA

https://blog.sekoia.io/sneaky-2fa-exposing-a-new-aitm-phishing-as-a-service/

#detection #sneaky2fa
Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
In this blog post, learn about Sneaky 2FA, a new Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts.
blog.sekoia.io
January 16, 2025 at 4:17 PM
DataDog is tracking an AitM phishing campaign targeting the AWS Console login panel, with submitted credentials being abused as fast as 20 minutes after compromise.

securitylabs.datadoghq.com/articles/beh...
March 10, 2026 at 10:48 AM
Russia is allegedly using its backdoor access to local ISPs to install malware on the systems of foreign embassies in Moscow, Microsoft said on Thursday

therecord.media/russia-fsb-t...
Microsoft: Kremlin monitors foreign embassies in Moscow through cyber-espionage at ISP level
A Russian state-backed hacking group known as Secret Blizzard or Turla has been aiming adversary-in-the-middle (AiTM) attacks at foreign embassies in Moscow, Microsoft researchers said.
therecord.media
July 31, 2025 at 4:06 PM
TRAC Labs has published a breakdown of WikiKit, a phishing kit with a weird quirk of redirecting victims to Wikipedia pages if JavaScript is disabled in their browser or if the phishing link is invalid

trac-labs.com/wikikit-aitm...
WikiKit AiTM Phishing Kit: Where Links Tell Lies
TRAC Labs has recently identified a phishing kit, which we have named WikiKit because of its functionality to redirect to Wikipedia …
trac-labs.com
December 26, 2024 at 1:47 PM
Microsoft Threat Intelligence has uncovered a cyberespionage campaign by the Russian state actor we track as Secret Blizzard targeting embassies in Moscow using an adversary-in-the-middle (AiTM) position to deploy their custom ApolloShadow malware. msft.it/63320sJmHK
Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats | Microsoft Security Blog
Microsoft Threat Intelligence has uncovered a cyberespionage campaign by the Russian state actor we track as Secret Blizzard that has been ongoing since at least 2024, targeting embassies in Moscow using an adversary-in-the-middle (AiTM) position to deploy their custom ApolloShadow malware.
msft.it
July 31, 2025 at 4:02 PM
We love a good reconnaissance tool like DNS Triage!

More Michael:
How to Test AitM e Without Hacking Tools -- www.youtube.com/watch?v=Esu8...

AitM: Post-Exploitation -- www.youtube.com/watch?v=WY4m...

OPSEC Fundamentals Red Teams -- www.youtube.com/watch?v=AHwf...
December 17, 2025 at 5:58 PM
Microsoft Defender researchers uncovered a multi‑stage adversary‑in‑the‑middle (AiTM) phishing and business email compromise (BEC) campaign targeting the energy sector. msft.it/63320QD9Tq
Resurgence of a multi‑stage AiTM phishing and BEC campaign abusing SharePoint  | Microsoft Security Blog
Microsoft Defender Researchers uncovered a multi‑stage AiTM phishing and business email compromise (BEC) campaign targeting multiple organizations in the energy sector.
msft.it
January 23, 2026 at 11:34 PM
A few weeks ago, we published our global analysis of Adversary-in-the-Middle #phishing threats, providing actionable intelligence on multiple #AitM phishing kits.

This report includes 11 sheets covering the most widespread #AitM phishing kits as of Q1 2025.
July 8, 2025 at 7:53 AM
official bsky app sanitizes anyway, but dollars to donuts someone's trying to figure out a way to do an AitM
January 8, 2026 at 3:11 AM
“Rockstar 2FA” Phishing-as-a-Service Steals Microsoft 365 Credentials Via AiTM Attacks
"Rockstar 2FA" Phishing-as-a-Service Steals Microsoft 365 Credentials Via AiTM Attacks
Cybersecurity experts are concerned about the connection between a sophisticated phishing kit known as 'Rockstar 2FA'.
cybersecuritynews.com
December 1, 2024 at 9:42 AM
Aí que entra a parte de opiniões rs mas independente do meu desgostos, ela é muito influente e numa faixa etária importante nessas eleições, vamos ver o que vem aíTM
September 11, 2024 at 3:57 AM