Skip to content

IdP in the middle attack #24

@TomCJones

Description

@TomCJones

Here's a successful attack that appears (to me) to be an identify provider spoofing attack.
I think that we might need to add this to things like DC API and FedCM.
The quoted success rate is 50%

https://cybersecuritynews.com/threat-actors-impersonating-microsoft-oauth

"The researchers observed that while most campaigns impersonate generic enterprise applications, some attackers customize their lures based on specific software used in targeted industries, demonstrating a sophisticated understanding of their victims’ operational environments. The financial and operational impact has been substantial, with researchers documenting attempted account compromises affecting nearly 3,000 user accounts across more than 900 Microsoft 365 environments. Perhaps most concerning is the campaign’s confirmed success rate exceeding 50%, highlighting the effectiveness of this hybrid attack methodology that combines email-based social engineering with cloud application abuse."

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions