Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'mfa bypass'

View all threats tagged with 'mfa bypass'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mfa bypass

Threats Tagged 'mfa bypass'

Click on any threat for detailed analysis and mitigation recommendations

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
0

Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints.

Join the discussion
Inside a Global Procurement-Themed AiTM Phishing Campaign
0

A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.

Join the discussion
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
0

A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.

Join the discussion
Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge
0

Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: mfa bypass
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses