{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro"},"incident":{"slug":"2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro","title":"EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts","date":"2023-08","date_precision":"month","year":2023,"victim_org":"More than 100 organisations worldwide (Proofpoint-tracked campaign)","sector":"Technology","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.","how_it_worked":"Emails impersonated widely trusted services such as Adobe, DocuSign and Concur, and pushed recipients through redirect chains to an EvilProxy page that relayed the real Microsoft 365 log-in. Victims entered their password and completed their genuine MFA challenge, and the proxy captured the resulting session cookie, so MFA provided no protection. The campaign filtered its own traffic, screening out non-target regions and security-research infrastructure, and deliberately concentrated on executives whose mailboxes carry payment authority and confidential deal information. Successful intrusions were consolidated by enrolling an attacker-controlled MFA method, converting a one-time theft into durable access.","lessons":"Phishing-resistant FIDO2 credentials for high-value roles, and alerting whenever a new MFA method is registered on an executive account, are the controls that matter here.","confidence":"Confirmed","sources":[{"title":"EvilProxy Phishing Used for Cloud Account Takeover Campaign","url":"https://www.proofpoint.com/us/blog/email-and-cloud-threats/cloud-account-takeover-campaign-leveraging-evilproxy-targets-top-level","publisher":"Proofpoint"},{"title":"EvilProxy phishing campaign targets 120,000 Microsoft 365 users","url":"https://www.bleepingcomputer.com/news/security/evilproxy-phishing-campaign-targets-120-000-microsoft-365-users/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro"}}