Found On Dark Web: Beware Of Phishing – Hackers Are Finding New Ways To Bypass Two-Factor Authentication

2fa-hackers-thenextweb-com-2022-truth




New EvilProxy Phishing Service Allowing Cybercriminals to Bypass 2-Factor Security

Found On Dark Web: Beware Of Phishing – Hackers Are Finding New Ways To Bypass Two-Factor Authentication

Ravie Lakshmanan with The Hacker News reports:

2fa-hackers-thenextweb-com-2022-truth
IMAGE VIA thenextweb.com

A new phishing-as-a-service (PhaaS) toolkit dubbed EvilProxy is being advertised on the criminal underground as a means for threat actors to bypass two-factor authentication (2FA) protections employed against online services.

“EvilProxy actors are using reverse proxy and cookie injection methods to bypass 2FA authentication – proxifying victim’s session,” Resecurity researchers said in a Monday write-up.


earn free bitcoin

The platform generates phishing links that are nothing but cloned pages designed to compromise user accounts associated with Apple iCloud, Facebook, GoDaddy, GitHub, Google, Dropbox, Instagram, Microsoft, NPM, PyPI, RubyGems, Twitter, Yahoo, and Yandex, among others.

phishing-2fa-thehackernews-com-chart-2022-truth
IMAGE VIA thehackernews.com


EvilProxy is similar to adversary-in-the-middle (AiTM) attacks in that users interact with a malicious proxy server that acts as a go-between for the target website, covertly harvesting the credentials and 2FA passcodes entered in the login pages.

It’s offered on a subscription basis per service for a time period of 10, 20, or 31 days, with the kit available for $400 a month and accessed over the TOR anonymity network after the payment is arranged manually with an operator on Telegram. Attacks against Google accounts, in contrast, cost up to $600 per month.



Share this page to Telegram

Please use the buttons to TWEET & SHARE this post ... then leave your thoughts & feelings in the COMMENT SECTION by scrolling down ... finally If you haven't joined TRUTH PREMIUM, what are you waiting for?

CLICK HERE -->I Want Truth Premium

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments

MIKE LINDELL CANCELLED: Up to 66% Off Mike Lindell's MyPillow Promo Code ETERNAL


Join Our TRUTH INSIDER Email Newsletter For FREE!