Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts

The use of authentic HTTP client tools by cybercriminals to enable account takeover (ATO) assaults on Microsoft 365 systems is growing.

In order to carry out ATO attacks, enterprise security firm Proofpoint reported seeing campaigns that used the HTTP clients Axios and Node Fetch to send HTTP requests and retrieve HTTP replies from web servers.

According to security researcher Anna Akselevich, these tools, which were initially taken from open repositories like GitHub, are being utilized more and more in brute force and adversary-in-the-middle (AitM) assaults, which have resulted in a number of account takeover (ATO) events read more about Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *