Phishing-as-a-Service “Rockstar 2FA” Targets Microsoft 365 Users with AiTM Attacks
Researchers in cybersecurity are alerting people about malicious email campaigns that use the Rockstar 2FA phishing-as-a-service (PhaaS) toolset to obtain Microsoft 365 account credentials.
Even customers who have multi-factor authentication (MFA) set may still be at risk because this campaign uses an adversary-in-the-middle (AitM) assault that enables attackers to intercept user credentials and session cookies, according to Trustwave experts Diana Solomon and John Kevin Adriano.
It is believed that Rockstar 2FA is a modernized DadSec (also known as Phoenix) phishing kit. Under the name Storm-1575, Microsoft is keeping tabs on the creators and resellers of the Dadsec PhaaS platform read more about Phishing-as-a-Service "Rockstar 2FA" Targets Microsoft 365 Users with AiTM Attacks.
...

