The AiTM phishing campaign targets Google Workspace users in addition to Microsoft corporate email service users.
The threat actors behind a large-scale adversary-in-the-middle (AiTM) targeting corporate users of Microsoft email services have also targeted Google Workspace users.
“This campaign specifically targeted executives and other senior members of various organizations using Google Workspace,” Zscaler researchers Sudeep Singh and Jagadeeswar Ramanukolanu in a report published this month.

The AitM phishing attacks are said to have begun in mid-July 2022, following a similar modus operandi to that of a social engineering campaign designed to wipe users' Microsoft credentials and even bypass multi-factor authentication .
See also: Google: Repel record-breaking HTTPS DDoS attack
The Gmail AiTM also involves the use of compromised executive emails to conduct further phishing attacks by the threat actor, with the attacks also using several compromised domains as an intermediary URL redirector to take victims to the landing page.
The attack chains involve sending password expiration emails to potential targets that contain an embedded malicious link to supposedly “extend access,” which leads the recipient to open Google Ads and Snapchat to load the phishing page URL.

In addition to the overt redirection abuse, a second variant of the attacks relies on infected websites hosting a Base64 encoded version of the next-stage redirector and the victim's email address in the URL. This intermediate redirector is JavaScript that leads to a Gmail phishing page.
In one case highlighted by Zscaler, the redirector page used in the Microsoft AiTM on July 11, 2022, was updated to take the user to a Gmail AiTM, linking the two campaigns to the same threat actor.

See also: Phishing: Sharp increase in abuse of legitimate SaaS platforms
"There was also an infrastructure overlap and we even identified several cases where the threat actor switched from Microsoft AiTM phishing to Gmail phishing using the same infrastructure," the researchers said.
The findings indicate that multi-factor authentication safeguards alone cannot offer protection against advanced phishing attacks, requiring users to carefully check URLs before entering credentials and avoid opening attachments or clicking links in emails sent from untrusted or unknown sources.
Source: thehackernews.com
