Microsoft Defender uncovers new multi-stage phishing attack

June 15, 2023

Microsoft Defender Experts have uncovered a new multi-stage phishing attack targeting banking and financial institutions. The attack, which is believed to be the work of a threat actor known as Storm-1167, uses a variety of techniques to compromise user accounts and steal sensitive financial information.

The attack starts with a technique called AiTM (Authentication in the Middle). The attacker tricks users into visiting a fake website that looks like a legitimate service’s login page. By doing this, they can steal sensitive information like usernames, passwords, and credit card details.

The attacker tricks the user by sending an email with a harmful link. When the user clicks the link, they are taken to a fake login page that looks real. If the user enters their login information, the attacker can steal their account details, like passwords and Social Security numbers. They can also install malware on the user’s computer to gather more information, such as credit card numbers and bank statements.

To control the victim’s account longer, the attacker changes the account settings and adds a new authentication method without needing to re-authenticate. Then, they target the victim’s contacts by launching a large-scale phishing campaign.

The attacker uses information from previous emails to make the emails seem legitimate. They even resend to skeptical recipients, falsely confirming the emails’ legitimacy. To avoid detection, they delete undelivered, and out-of-office replies systematically.

The sources for this piece include an article in TechRepublic.

Top Stories

Related Articles

April 1, 2026 Anthropic has inadvertently exposed the full source code of its Claude Code tool for the second time more...

April 1, 2026 Cisco suffered a cyberattack after attackers used stolen credentials from a compromised developer tool to access its more...

March 30, 2026 Google has expanded its “Results about you” tool, allowing users to remove highly sensitive personal data, including more...

March 27, 2026 Microsoft is updating GitHub Copilot to train on real-world developer interactions, expanding beyond public code datasets to more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn