The Phishing Matryoshka: Unpacking a BEC to AiTM Nested Attack Chain
Article originally co-authored with Joseph Odyn at Exaforce: https://www.exaforce.com/blogs/aitm-phishing-matryoshka
Attack overview

Attack chain from email to credential theft




Deconstructing the attack

How Exaforce detected and responded

Protection strategies
Lessons from the phishing attempt
PreviousNow You See Me, Now You Don't - Analyzing an invisible Blockchain C2 implantNextIntroducing YetiHunter: An open-source tool to detect and hunt for suspicious activity in Snowflake
Last updated