Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

1
MFA and the prevention of AiTM
Post Flair (click to view more posts with a particular flair)
Post Body

Hey Redditors,

I need your advice.

Currently, I'm try to investigate the AiTM attack method in the Microsoft Cloud environment.

Some of my references I get my knowledge from are:

AiTM/ MFA phishing attacks in combination with "new" Microsoft protections (2024 edition) (jeffreyappel.nl)

From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud | Microsoft Security Blog

I recall my previous employer experiencing such an attack. A user received an email with a QR code, scanned it, and subsequently entered their username and password.

According to the user, the subsequent MFA prompt was NOT confirmed. I also remember seeing in the login-logs that MFA was not confirmed.

Despite this, the attacker was able to add a second factor, authenticate, and initiate a BEC.

My question is:

How could the attacker register a second factor and complete the login without full authentication process from the user?

From what I've read online so far, for me it’s not entirely clear how this is possible. Some ressources state that MFA confirmation is required, while others suggest it can be bypassed.

Can someone please explain this to me?

Thanks in advance!

Author
Account Strength
60%
Account Age
3 years
Verified Email
Yes
Verified Flair
No
Total Karma
65
Link Karma
31
Comment Karma
34
Profile updated: 6 days ago
Posts updated: 1 day ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
5 months ago