MFA Phishing

Scammers Use a Mix of Stolen Credentials, Inbox Rules, and a Rogue Outlook Client Install to Phish Internal and External Victims

Organizations that are not using Microsoft’s multi-factor authentication are finding themselves victims of credential attacks that involve threat actors installing Outlook on a controlled device.

originally published on

Related posts

Google Docs Comment Feature is the Key to a New Wave of Phishing Campaigns


[EYE OPENER] New EU Phishing Study Shows That Crowd-sourcing Phishing Alerts Is Successful


Traits of Most Scams
