Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

New AitM & BEC Attacks Targets Finance

June 12, 2023
Reading Time: 2 mins read
in Alerts

 

Microsoft has disclosed a new multi-stage adversary-in-the-middle (AitM) phishing and business email compromise (BEC) attack targeting banking and financial services organizations. The attack, known as Storm-1167, originated from a compromised trusted vendor and involved a series of AitM attacks and subsequent BEC activity across multiple organizations.

The attackers utilized an indirect proxy to tailor phishing pages and steal session cookies, showcasing the sophistication of AitM attacks. Unlike typical AitM campaigns, the attackers presented victims with a website mimicking the sign-in page of the targeted application, initiating an authentication session using the victim’s credentials. The harvested information was then used to gain unauthorized access to email inboxes, enabling the attackers to orchestrate BEC attacks.

In addition to stealing credentials, the attackers added a new SMS-based two-factor authentication method to target accounts, allowing them to sign in without raising suspicion. Microsoft’s analysis revealed that the attacker conducted a mass spam campaign, sending over 16,000 emails to the compromised user’s contacts within and outside the organization, as well as distribution lists.

The adversaries took measures to minimize detection, including responding to incoming emails and deleting them from the compromised mailbox. Subsequently, the recipients of the phishing emails were targeted with a second AitM attack, leading to the theft of their credentials and the initiation of another phishing campaign from a compromised account.

Microsoft emphasized the complexity of AitM and BEC threats, which exploit trusted relationships between vendors, suppliers, and partner organizations to perpetrate financial fraud.

This disclosure comes shortly after Microsoft’s warning about a surge in BEC attacks and the evolving tactics used by cybercriminals, such as leveraging platforms like BulletProftLink for large-scale malicious mail campaigns. The use of residential IP addresses was another tactic employed to make attack campaigns appear locally generated.

By purchasing IP addresses matching the victim’s location, BEC threat actors can obscure their movements, bypass “impossible travel” flags, and carry out further attacks.

Reference:
  • Detecting and mitigating a multi-stage AiTM phishing and BEC campaign 
Tags: AitMAuthenticationBECCredentialsCyber AlertCyber Alerts 2023cyberespionageJune 2023MicrosoftPhishingVulnerabilities
ADVERTISEMENT

Related Posts

Open VSX Flaw Allowed Extension Hijacks

Open VSX Flaw Allowed Extension Hijacks

June 27, 2025
Open VSX Flaw Allowed Extension Hijacks

nOAuth Flaw Allows Easy Account Takeover

June 27, 2025
Open VSX Flaw Allowed Extension Hijacks

Unpatchable Flaw In Hundreds Of Printers

June 27, 2025
New Malware Uses Prompts To Trick AI Tools

Fake Job Offers Hide North Korean Malware

June 26, 2025
New Malware Uses Prompts To Trick AI Tools

New Malware Uses Prompts To Trick AI Tools

June 26, 2025
New Malware Uses Prompts To Trick AI Tools

New Zero Day Flaw Hits Citrix NetScaler

June 26, 2025

Latest Alerts

nOAuth Flaw Allows Easy Account Takeover

Unpatchable Flaw In Hundreds Of Printers

Open VSX Flaw Allowed Extension Hijacks

Fake Job Offers Hide North Korean Malware

New Malware Uses Prompts To Trick AI Tools

New Zero Day Flaw Hits Citrix NetScaler

Subscribe to our newsletter

    Latest Incidents

    Hawaiian Airlines Hit By Cyberattack

    Qilin Ransomware Gang Hacks Estes Freight

    Generali Customer Data Exposed In Hack

    Resupply DeFi Protocol Hacked For $9.6M

    Cyberattack Hits South Tyrol Emergency Ops

    UK’s Glasgow City Council Hit By Cyberattack

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial