Skip to content

Topic

Adversary-in-the-Middle Phishing

Real-time relay of victim authentication through attacker infrastructure to harvest credentials, MFA codes and the resulting session.

Current stories

securityConfirmed3 publishers

Storm-3121 callers demand an urgent passkey update to harvest Microsoft 365 session tokens

Microsoft has tracked passkey- and SSO-themed help desk impersonation since May 2026, with the calls steering employees into adversary-in-the-middle proxies and device-code grants that hand over live Microsoft 365 sessions.

Perspective Coverage

3 publishers
Builder
Builder 25%
Operator
Operator 63%
Investor
Investor 12%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence70
securityConfirmed7 publishers

TA419 courts AI policy experts before phishing their cloud accounts

Proofpoint says China-aligned TA419 has posed as a former White House official and an Anthropic employee to phish AI policy experts since at least April 2025. The first approach asks for nothing; the credential-stealing link follows only after a target replies.

Perspective Coverage

7 publishers
Builder
Builder 28%
Operator
Operator 59%
Investor
Investor 13%

Reality

Evidence62
Adoption
Insufficient
Hype gap+20
Incentives30
Confidence65
buildOne report1 publisher

MFA-relaying proxy kits make up 44.6% of phishing techniques in Microsoft's 2026 report

Microsoft's 2026 Digital Defense Report puts MFA-relaying proxy kits at 44.6% of phishing techniques, as phishing rose to 23% of its incident cases. SMS codes and push approvals pass straight through those proxies, so protecting company email now means passkeys or FIDO2 keys, starting with admins and finance staff.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+5
Incentives40
Confidence55
securityConfirmed3 publishers

PREY-0058 phones executives to harvest Microsoft 365 session tokens

Arctic Wolf says the cluster it tracks as PREY-0058 deploys no malware at all. A call from fake IT leads to a proxied login page, and the stolen session token comes back from inside the victim's own ASN.

Perspective Coverage

3 publishers
Builder
Builder 17%
Operator
Operator 75%
Investor
Investor 8%

Reality

Evidence62
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence60
securityConfirmed3 publishers

BigBear's phishing panel disables WebAuthn in the browser to beat MFA at 258 organizations

CloudSEK took administrator access to the panel and counted 5,137 stolen records coming off 42 VPS nodes into five leasing affiliates' Telegram bots, with the phishing pages dark for three weeks while the panel itself stays reachable.

Perspective Coverage

3 publishers
Builder
Builder 30%
Operator
Operator 60%
Investor
Investor 10%

Reality

Evidence55
Adoption30
Hype gap+25
Incentives40
Confidence60