2026年9月10日

Stay alert: How hackers bypass verification to steal credentials — common tactics and key defenses.

Neowin reports that Microsoft Defender security researchers recently uncovered a malicious campaign ...

Neowin reports that Microsoft Defender security researchers recently uncovered a malicious campaign targeting energy companies. The attackers used an Adversary-in-the-Middle (AiTM) technique to steal employee credentials and bypass multi-factor authentication (MFA).

According to the report, the operation often starts with a “seed” or “patient-zero” account. Attackers use social engineering to compromise one employee account, then leverage it to access additional internal mailboxes, harvest credentials, and expand laterally—ultimately enabling MFA bypass.

Next, the compromised account is used to send phishing emails at scale, disguised as SharePoint document-sharing notifications. Victims who click the link are redirected to a spoofed site that prompts them to enter usernames and passwords. Critically, attackers also steal session cookies—tokens that maintain an authenticated session—allowing them to reuse the session even when MFA is enabled.

After gaining access to multiple legitimate accounts, attackers create inbox rules to auto-delete incoming mail and mark messages as “read,” reducing the chances of detection. They then propagate the attack by emailing contacts in the victim’s address book—reportedly up to 600 phishing emails per victim—to drive chained spread.

To further cover tracks, the attackers monitor compromised inboxes and delete bounce-back messages and “out-of-office” auto-replies. If recipients become suspicious and ask questions, the attackers may impersonate the victim to respond that everything is normal, then delete the conversation afterward.

Microsoft advised impacted organizations to revoke all session cookies, remove attacker-created mailbox rules, and check for unauthorized changes to MFA settings. The company emphasized that simply resetting passwords is not sufficient in this scenario.

接著讀