VoidProxy Phishing Campaign Steals Microsoft, Google Credentials Bypassing MFA
VoidProxy Phishing Campaign Steals Microsoft, Google Credentials Bypassing MFA

VoidProxy Phishing Campaign Steals Microsoft, Google Credentials Bypassing MFA

News summary

Security researchers from Okta Threat Intelligence have uncovered a sophisticated phishing-as-a-service platform called VoidProxy, which targets Microsoft 365 and Google accounts, including those protected by third-party single sign-on (SSO) providers like Okta. VoidProxy employs adversary-in-the-middle (AitM) tactics to intercept and steal credentials, multi-factor authentication (MFA) codes, and session cookies in real time, effectively bypassing common MFA methods such as SMS codes and one-time passwords. The phishing campaigns use compromised legitimate email service providers to send emails containing shortened links, which redirect victims through multiple stages, including Cloudflare CAPTCHA challenges, to evade detection and bot traffic. Once users enter their credentials on convincing fake login pages, VoidProxy proxies the authentication requests to legitimate servers, capturing session tokens that enable attackers to hijack sessions and gain unauthorized access. This PhaaS platform leverages Cloudflare Workers and disposable domains to conceal its infrastructure, making it difficult for security teams to analyze and block the attacks. Experts recommend adopting phishing-resistant authentication methods and robust security awareness training to mitigate risks posed by VoidProxy and similar AitM phishing threats.

Story Coverage
Bias Distribution
100% Left
Information Sources
daae85f0-2883-42fc-b085-888140adf30d
Left 100%
Coverage Details
Total News Sources
1
Left
1
Center
0
Right
0
Unrated
0
Last Updated
1 day ago
Bias Distribution
100% Left
Related News
Daily Index

Negative

25Serious

Neutral

Optimistic

Positive

Ask VT AI
Story Coverage

Related Topics

Subscribe

Stay in the know

Get the latest news, exclusive insights, and curated content delivered straight to your inbox.

Present

Gift Subscriptions

The perfect gift for understanding
news from all angles.

Related News
Recommended News