Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms

Microsoft has issued a warning on a multi-stage adversary-in-the-middle (AitM) phishing and business email compromise (BEC) campaign that targets several energy-related businesses.

According to the Microsoft Defender Security Research Team, the campaign leveraged inbox rule creation to be persistent and avoid user knowledge, and it exploited SharePoint file-sharing capabilities to distribute phishing payloads. The attack evolved into numerous organizations’ worth of AitM attacks and subsequent BEC activity.

In an attempt to cast a wide net and expand the campaign’s scope, it has been discovered that the unknown attackers use the victim’s trusted internal identities to conduct extensive intra-organizational and external phishing as part of post-exploitation activity after the initial penetration read more about Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *