ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Man-in-the-Middle Phishing Attack

mediumPhishing & fraudimportance 30
Full article142 words · extracted from schneier.com · click to collapse

Here’s a phishing campaign that uses a man-in-the-middle attack to defeat multi-factor authentication:

Microsoft observed a campaign that inserted an attacker-controlled proxy site between the account users and the work server they attempted to log into. When the user entered a password into the proxy site, the proxy site sent it to the real server and then relayed the real server’s response back to the user. Once the authentication was completed, the threat actor stole the session cookie the legitimate site sent, so the user doesn’t need to be reauthenticated at every new page visited. The campaign began with a phishing email with an HTML attachment leading to the proxy server.

Tags: authentication, man-in-the-middle attacks, phishing, scams, two-factor authentication

Posted on August 25, 2022 at 6:45 AM29 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2022/08/man-in-the-middle-phishing-attack.html