Researchers at Lexfo have discovered three advanced phishing kits leveraging open-source components, primarily built on the Evilginx adversary-in-the-middle attack framework. These kits are capable of intercepting live Microsoft 365 authentication sessions, capturing session cookies and OAuth tokens in real-time, effectively bypassing multi-factor authentication. The phishing kits also utilize AI to craft personalized phishing lures, employing diverse delivery methods such as dynamically generated PDFs, DOCX, and other attachments. They also include AI-generated voicemail lures and use techniques like HTML email conversion to images for evading spam filters. The researchers highlight the alarming ease of access to these tools, which are available on platforms like GitHub and Telegram, drastically lowering the barriers for threat actors to execute these campaigns. Organizations are advised to assume that these sophisticated phishing methods are within reach of any attacker and to adjust their detection and response strategies accordingly.
Open-Source Phishing Kits Exploit Microsoft 365 Authentication
Open-source AiTM phishing kits proxy live Microsoft 365 auth sessions, capturing tokens and bypassing MFA protections.


