• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Microsoft reveals massive phishing campaign, victims can still be compromised even with multi-factor authentication enabled

Microsoft reveals massive phishing campaign, victims can still be compromised even with multi-factor authentication enabled

Claire by Claire
July 13, 2022 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

In recent years, various technology companies have been advocating that users turn on multi-factor authentication to improve the security of personal accounts. However, multi-factor accounts only increase the difficulty of intrusion, which does not mean that they are immune to all viruses. Recently, Microsoft disclosed a large-scale global phishing attack that can still hijack user accounts even if multi-factor authentication protection is enabled.

Microsoft reveals massive phishing campaign, victims can still be compromised even with multi-factor authentication enabled

Multi-factor authentication, also known as two-factor authentication, MFA or 2FA, is the current mainstream account security standard. In addition to traditional passwords, it also requires users to use things they own or control, such as physical security keys, fingerprints, facial recognition or retinal scans to assist in verifying their identity. The widespread use of MFA technology has added an additional barrier to account security and made it more difficult for hackers to break into user accounts, but now attackers have found ways to fight back.

Microsoft observed a campaign that has targeted more than 10,000 organizations since last September, tricking employees into sending money to hackers by accessing victim email accounts. This activity inserts an attacker-controlled proxy website between the account user and the working server they are trying to log in to. When the user enters their password into the proxy website, the proxy website first sends it to the real server – and then forwards the server’s response back to the user. Once the authentication is complete, the attacker steals the legitimate website session cookie so the user does not need to re-authenticate with each new web page. It all started with a phishing email with an HTML attachment pointing to a proxy server.

▲Sample phishing email with HTML file attachment

in microsoftAn official blog post, members of the Microsoft 365 Defender research team and the Microsoft Threat Intelligence Center mentioned that after first logging into a compromised account on a phishing website, attackers used stolen session cookies to authenticate to Outlook online. In many cases, cookies have MFA claims, which means that even if an organization adopts an MFA policy, attackers can use session cookies to gain access on behalf of compromised accounts.

▲ AiTM phishing website intercepts the authentication process.

In the days after the stolen cookies, threat actors access employee email accounts and look for messages used in business email compromise scams, which trick targets into transferring large sums of money to accounts they believe belong to colleagues or business partners. The attackers used these emails and the identities of the compromised employees to persuade them to pay. In order to prevent hacked employees from being discovered, the threat actors established inbox rules to automatically transfer specific emails to the archive folder and mark them as read. In the next few days, the attackers would log in regularly to check whether the email rules they created were functioning properly.

▲ Overview of the AiTM phishing campaign and subsequent BEC.

The blog post also stated that employees can easily fall into this type of scam because the volume of emails and workload often makes it difficult for users to confirm when information is authentic. One of the few suspicious visual elements in the entire scam is the function variable name used in the login page of the agency website. Enabling MFA basically indicates that the user or organization has a high level of awareness when it comes to cybersecurity. However, given the opaque nature of most organization-specific login pages, even a crude function variable name may make someone unaware of a compromise. To protect against such attacks, Microsoft recommends using phish-resistant MFA with certificate-based authentication and FIDO v2.0 support for higher protection. 

Source: KOCPC Chinese

Tags: 2FAe-mailInternet fraudMicrosoftTwo-step verification

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology