New VoidProxy phishing service targets Microsoft 365, Google accounts

New Phishing Service VoidProxy Targets Microsoft 365 and Google Accounts Using Advanced Techniques
Photo: BleepingComputer

New Phishing Service VoidProxy Targets Microsoft 365 and Google Accounts Using Advanced Techniques

A newly discovered phishing-as-a-service (PhaaS) platform called VoidProxy is targeting Microsoft 365 and Google accounts, including those protected by third-party SSO providers like Okta. Researchers at Okta Threat Intelligence discovered this sophisticated and evasive service, which employs adversary-in-the-middle (AitM) tactics. The attack begins with emails from compromised accounts at popular email service providers, which contain shortened links leading to phishing sites. These sites are hosted on low-cost domains with Cloudflare protection, hiding their true origins. Users are first shown a CAPTCHA to increase legitimacy, and those who are targeted by the phishing attack are presented with fake login pages mimicking Microsoft or Google login forms. For federated accounts using Okta’s SSO, the attack continues with a second stage where attackers impersonate Okta’s authentication process. During this process, VoidProxy intercepts credentials, MFA codes, and session cookies in real time. These intercepted credentials are made accessible to attackers via the platform’s admin panel. The attack does not affect users with phishing-resistant authentication methods like Okta FastPass. Researchers recommend several defenses against such attacks, including restricting sensitive apps to managed devices and enforcing risk-based access controls.

Leave a Reply

Your email address will not be published. Required fields are marked *