Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attack combined adversary-in-the-middle (AitM) phishing with a modified Frameless BitB toolkit. Frameless BitB avoids iframes and supports Evilginx-based proxying of Microsoft login pages.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The link ultimately led to a fake OneDrive AitM credential phishing page designed to gain access to the target’s cloud account.
The campaign spoofed Lynne Edwards Parker, Heidi Crebo-Rediker, and a senior Anthropic employee; the landing page performed a Cloudflare Turnstile check behind a phony OneDrive loading screen.
Because it forwards the victim's Microsoft 365 login to Microsoft in real time, the password, multifactor authentication (MFA) code and conditional access checks all pass.
A counterfeit Microsoft login pop-up placed over a OneDrive-lookalike page relayed the login to genuine Microsoft infrastructure, allowing harvesting of Microsoft 365 passwords, MFA codes, and session cookies.
A custom script built into the kit reports the victim’s progress to the attackers, gives them a live view of the session, accepts the “Keep me signed in” prompt and submits one-time codes as soon as they validate.
The phishing page relayed the login to genuine Microsoft infrastructure, allowing the harvesting of Microsoft 365 passwords, MFA codes, and session cookies.
Credentials entered in that window are relayed to Microsoft’s servers, so the password, the MFA code and conditional access checks would all go through.
Because it forwards the victim's Microsoft 365 login to Microsoft in real time, the password, multifactor authentication (MFA) code and conditional access checks all pass.
A counterfeit Microsoft login pop-up placed over a OneDrive-lookalike page relayed the login to genuine Microsoft infrastructure, allowing harvesting of Microsoft 365 passwords, MFA codes, and session cookies.
Frameless BitB ... contains a Browser-in-the-Browser (BitB) overlay [and] an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser-in-the-browser/AitM phishing toolkit used to present a convincing fake browser login window while proxying legitimate Microsoft authentication and capturing authenticated cloud-session cookies.
A browser-in-the-browser phishing toolkit used to present a convincing embedded browser/login window and proxy genuine Microsoft authentication, enabling capture of authenticated cloud session cookies rather than only credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.