You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
aitm
About this tag
The aitm tag on WindowsForum.com covers adversary-in-the-middle (AiTM) phishing attacks that target Microsoft 365 credentials and bypass multi-factor authentication (MFA). Discussions include the Rockstar 2FA and VoidProxy phishing-as-a-service platforms, which intercept sign-ins in real time, harvest session cookies, and enable account takeover without passwords. Other threads examine how Microsoft OAuth applications are weaponized to subvert MFA, and why Microsoft datacenter IPs appear in sign-in logs. The tag provides technical explanations of AiTM mechanics, real-world attack campaigns, and practical steps for consumers and IT administrators to reduce exposure.
A growing number of Microsoft account holders report successful sign‑ins from IP addresses inside Microsoft’s own network despite having two‑factor authentication enabled — an uptick of incidents first detailed in a German investigation and corroborated by threads on Reddit and Microsoft’s own...
A new, industrialized phishing service called VoidProxy is being used by multiple criminal groups to intercept Google and Microsoft sign-ins in real time, harvest credentials, MFA responses and — critically — session cookies that let attackers impersonate users without needing passwords or...
Threat actors in 2025 have harnessed a new caliber of cyberattack, subverting enterprise identity and trust by weaponizing Microsoft OAuth applications to bypass even the most robust multi-factor authentication (MFA) defenses. This emerging campaign, tracked by Proofpoint and other leading...
A new and sophisticated species has entered the phishing ecosystem, and its name is Tycoon 2FA. At a time when digital security feels like a relentless arms race, this phishing-as-a-service (PhaaS) platform epitomizes just how quickly adversaries adapt to modern defenses—forging an unsettling...
In a grim reminder of cybersecurity's ever-evolving landscape, researchers have uncovered a new and sophisticated adversary-in-the-middle (AiTM) cyberattack targeting Microsoft 365 credentials. This campaign is powered by the upgraded Rockstar 2FA, a phishing-as-a-service (PhaaS) platform that...
In a chilling revelation for Microsoft 365 users, security researchers have unveiled a sophisticated phishing toolkit known as "Rockstar 2FA" that circumvents multi-factor authentication (MFA) in a strikingly clever manner. This "Phishing-as-a-Service" (PhaaS) offering demonstrates how...