What happened
Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.
How the deception worked
Emails impersonated widely trusted services such as Adobe, DocuSign and Concur, and pushed recipients through redirect chains to an EvilProxy page that relayed the real Microsoft 365 log-in. Victims entered their password and completed their genuine MFA challenge, and the proxy captured the resulting session cookie, so MFA provided no protection. The campaign filtered its own traffic, screening out non-target regions and security-research infrastructure, and deliberately concentrated on executives whose mailboxes carry payment authority and confidential deal information. Successful intrusions were consolidated by enrolling an attacker-controlled MFA method, converting a one-time theft into durable access.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant FIDO2 credentials for high-value roles, and alerting whenever a new MFA method is registered on an executive account, are the controls that matter here.
Sources (2)
- EvilProxy Phishing Used for Cloud Account Takeover CampaignProofpoint·proofpoint.comOpen ↗
- EvilProxy phishing campaign targets 120,000 Microsoft 365 usersBleepingComputer·bleepingcomputer.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.