Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
In the background, however, the attacker captures every step in transit, including the username, password, MFA response, and resulting session cookie. Once that cookie is stolen, it can be replayed to access the account as an authenticated user.
Modern phishing kits are far removed from the static HTML credential harvesters of a decade ago. Their main innovation lies in the AiTM architecture, which allows attackers to capture not just usernames and passwords, but also the authenticated session cookie created after a successful MFA challenge.
Modern phishing kits are far removed from the static HTML credential harvesters of a decade ago. Their main innovation lies in the AiTM architecture, which allows attackers to capture not just usernames and passwords, but also the authenticated session cookie created after a successful MFA challenge.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.