Sunday , March 16 2025

How AitM Phishing Attacks Bypass EDR and MFA-How to Fight (Video)

Attackers are using more phishing toolkits (open-source, commercial, and criminal) to carry out adversary-in-the-middle attacks. Attackers can use AitM to steal both login information and active sessions. This lets them bypass security measures like MFA, EDR, and email filtering.

What is AitM phishing?

Researcher found non protected database form ESHYFT containig 86000 records

Cybersecurity researcher Jeremiah Fowler found and reported a non-password-protected database with over 86,000 records belonging to ESHYFT, a New Jersey-based...
Read More
Researcher found non protected database form ESHYFT containig 86000 records

CVE-2024-55591 and CVE-2025-24472
New SuperBlack ransomware exploits Fortinet flaws

Forescout Research- Vedere Labs identified a series of intrusion based on two Fortinet vulnerabilities which began with the exploitation of...
Read More
CVE-2024-55591 and CVE-2025-24472  New SuperBlack ransomware exploits Fortinet flaws

CVE-2025-25291 & CVE-2025-25292
Attention! GitLab Patched Critical Authentication Bypass Flaws

GitLab has released versions 17.9.2, 17.8.5, and 17.7.7 for its Community and Enterprise Editions to fix security vulnerabilities, including a...
Read More
CVE-2025-25291 & CVE-2025-25292  Attention! GitLab Patched Critical Authentication Bypass Flaws

CVE-2025-20138
Cisco released High Security Alert for IOS XR Software

Cisco has issued a security advisory for a high-severity vulnerability in its IOS XR Software, labeled CVE-2025-20138, with a CVSS...
Read More
CVE-2025-20138  Cisco released High Security Alert for IOS XR Software

400+ IPs Exploiting Multiple SSRF Vulnerabilities

GreyNoise warns of a coordinated increase in the exploitation of Server-Side Request Forgery (SSRF) vulnerabilities across various platforms. "At least...
Read More
400+ IPs Exploiting Multiple SSRF Vulnerabilities

NVIDIA has released update for NVIDIA Riva

NVIDIA has released a software update for Riva to fix security vulnerabilities that could allow privilege escalation, data tampering, denial...
Read More
NVIDIA has released update for NVIDIA Riva

CVE-2025-24201
Apple fixes 0-day exploited in “extremely sophisticated attack”

On Tuesday, Apple fixed a critical zero-day vulnerability affecting nearly all supported iPhones and iPads. The company noted that it...
Read More
CVE-2025-24201  Apple fixes 0-day exploited in “extremely sophisticated attack”

Microsoft’s March 2025 updates fix 7 zero-day, 57 flaws

Microsoft's March 2025 Patch Tuesday update fixes 57 flaws, including seven zero-day exploits, six of which are actively being exploited....
Read More
Microsoft’s March 2025 updates fix 7 zero-day, 57 flaws

Ballista Botnet infects 6000 Unpatched TP-Link Routers

Cato CRTL team said, a new botnet campaign dubbed Ballista target the unpatched TP-Link Archer routers. CVE-2023-1389 is a serious...
Read More
Ballista Botnet infects 6000 Unpatched TP-Link Routers

CVE-2025-24813
Flaw in Apache Tomcat Exposes Servers to RCE

A critical vulnerability, CVE-2025-24813, has been found in Apache Tomcat, which could let attackers execute remote code, leak sensitive data,...
Read More
CVE-2025-24813  Flaw in Apache Tomcat Exposes Servers to RCE

AitM phishing uses specialized tools to intercept information between the target and a real application login portal.

Because the user is logging into the real site through a proxy, they will see the page exactly as expected. For instance, they will see their real emails when accessing webmail, and their real files when accessing the cloud file store.

AitM feels more authentic and the compromise is less noticeable to the user. Unfortunately, since the attacker is in the middle of the connection, they can see all interactions and take control of the authenticated session to gain control of the user account.

Although the access is temporary for the attacker, authenticated sessions can often last up to 30 days or more if kept active. Moreover, there are various persistence techniques that enable the attacker to maintain access to the user account or targeted application indefinitely.

How do AitM toolkits work?
There are two main techniques used for AitM phishing: Reverse web proxies (classic AitM) and Browser-in-the-Middle (BitM) techniques. AitM toolkits have two main variants.

Reverse web proxy:
This is a very effective method used by attackers. When a victim goes to a malicious website, the requests made by their browser are passed through the malicious site to the actual website. The malicious site then sends the request to the real website, receives the response, and sends it back to the victim.

Open-source tools like Modlishka, Muraena, and Evilginx demonstrate this method. In the criminal world, similar private toolsets have been used in many breaches in the past.

BitM:

Instead of being a reverse web proxy, this method deceives a target into remotely controlling the attacker’s browser using desktop screen sharing and control methods such as VNC and RDP. This allows the attacker to gather not only the username and password, but also all other linked secrets and tokens used for the login.

The victim in this case is unknowingly using the attacker’s browser to log in to the legitimate application. It’s like the attacker giving their laptop to the victim to log in and then taking it back.

The most common way to implement this technique is by using the open-source project called noVNC, a JavaScript-based VNC client that enables VNC usage in web browsers. An example of an offensive tool using this is EvilnoVNC, which creates Docker instances of VNC, provides access to them, and records keystrokes and cookies to compromise accounts. Click here to read full report.

Source: Thehackernews

Check Also

NTT

Cyber attack at Japanese telecom leader NTT hits 18,000 companies

NTT Communications Corporation discovered illegal access to its facilities on February 5 and confirmed on …

Leave a Reply

Your email address will not be published. Required fields are marked *