Hackers Seek To Bypass Multi-Factor Authentication

Share post:

Cyber security experts at Proofpoint say cybercriminals are now updating their tactics to bypass multi-factor authentication (MFA) systems.

This can be seen in the updated version of phishing kits used by attackers. Attackers can use phishing kits to take advantage of reverse proxy servers instead of relying on the creation of a target web page.

“The threat actors can just purchase space on a shared hosting server or cloud host and upload the phish kit and reverse proxy infrastructure on their own machines. Or compromise and use that host. It takes about an hour to purchase a domain, get a VPS [virtual private server], install the phish kit, web server, reverse proxy, and DNS configurations. By exploiting this situation with phishing kits, attackers can not only steal usernames and passwords, but also session cookies, enabling access to the targeted account,” said Sherrod DeGrippo, VP of threat protection and detection at Proofpoint.

The tactic is currently rare, but researchers warned that cybercriminals may eventually be forced to adapt if they work to bypass multi-factor authentication.

For more information read the original story in ZDNet.

SUBSCRIBE NOW

Related articles

Chinese government websites “Riddled with security flaws” say researchers

A recent study conducted by researchers from the Harbin Institute of Technology reveals significant security issues plaguing Chinese...

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways