
“Dozens” of organizations around the world have been targeted as part of a widespread business email compromise (BEC) campaign involving the use of adversary man-in-the-middle (AitM) techniques to carry out attacks.
“After a successful phishing attempt, the attacker first gains access to one of the victim’s employee accounts and uses a ‘man-in-the-middle’ to bypass Office365 authentication and gain permanent access to that account. The attack “performed the attack,” said the Sygnia researchers. The report was shared with The Hacker News.
“Once the attackers have gained persistence, they can steal data from compromised accounts and use that access to spread phishing attacks against employees of other victims and several external target organizations. I did.”

The findings come less than a week after Microsoft detailed a similar combination of AitM phishing and BEC attacks targeting banking and financial services organizations.
BEC scams typically involve emails tricking targets into transferring money or divulging sensitive company information. In addition to personalizing the email to the intended victim, the attacker can also impersonate a trusted person to accomplish their goals.
It involves seizing control of an account through an elaborate social engineering scheme, after which the fraudster emails the company’s customers and suppliers with bogus invoices demanding payment to a fraudulent bank account. This can be achieved by
In the attack chain documented by Sygnia, the attackers sent phishing emails containing links purported to be “shared documents,” and eventually AitM, designed to collect entered credentials and one-time passwords. It has been observed to redirect victims to phishing pages.
🔐 Mastering API Security: Understanding Your True Attack Surface
Discover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!
join the session
In addition, threat actors abused temporary access to compromised accounts to register new multi-factor authentication (MFA) devices in order to gain a permanent remote presence from another IP address located in Australia. It is said that
“In addition to exfiltrating sensitive data from victim accounts, attackers can use this access to send new phishing emails containing new malicious links to dozens of client employees and additional target organizations. to,” said the Signia researcher.
The Israeli cybersecurity firm also said the phishing emails spread in a “worm-like manner” from the targeted company to another and between employees within the same company. The exact size of the campaign is unknown at this time.