Sponsored: Prepare For The Storm With MyPatriotSupply's Emergency Food Kits Today - Get The Best Deal Here


old eternal affairs truth media header banner

Found On Dark Web: Beware Of Phishing – Hackers Are Finding New Ways To Bypass Two-Factor Authentication

2fa-hackers-thenextweb-com-2022-truth

New EvilProxy Phishing Service Allowing Cybercriminals to Bypass 2-Factor Security

Found On Dark Web: Beware Of Phishing – Hackers Are Finding New Ways To Bypass Two-Factor Authentication

Ravie Lakshmanan with The Hacker News reports:

2fa-hackers-thenextweb-com-2022-truth
IMAGE VIA thenextweb.com

A new phishing-as-a-service (PhaaS) toolkit dubbed EvilProxy is being advertised on the criminal underground as a means for threat actors to bypass two-factor authentication (2FA) protections employed against online services.

“EvilProxy actors are using reverse proxy and cookie injection methods to bypass 2FA authentication – proxifying victim’s session,” Resecurity researchers said in a Monday write-up.

The platform generates phishing links that are nothing but cloned pages designed to compromise user accounts associated with Apple iCloud, Facebook, GoDaddy, GitHub, Google, Dropbox, Instagram, Microsoft, NPM, PyPI, RubyGems, Twitter, Yahoo, and Yandex, among others.

phishing-2fa-thehackernews-com-chart-2022-truth
IMAGE VIA thehackernews.com


EvilProxy is similar to adversary-in-the-middle (AiTM) attacks in that users interact with a malicious proxy server that acts as a go-between for the target website, covertly harvesting the credentials and 2FA passcodes entered in the login pages.

It’s offered on a subscription basis per service for a time period of 10, 20, or 31 days, with the kit available for $400 a month and accessed over the TOR anonymity network after the payment is arranged manually with an operator on Telegram. Attacks against Google accounts, in contrast, cost up to $600 per month.




Truth Premium
CLICK HERE -->I Want Truth Premium

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments


Please use the buttons to TWEET & SHARE this valuable content ... then leave your thoughts & feelings in the COMMENT SECTION ... finally If you haven't joined TRUTH PREMIUM, what are you waiting for?