By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Exposing VENOM: PhaaS Platform Targeting C-Suite Credentials” (June 26, 2026)

TL;DR: A five-month campaign targeted C-suite executives by name, used a previously undocumented phishing-as-a-service platform called VENOM, and combined evasion tactics with real-time authentication interception to turn a single login into persistent account access, according to Abnormal AI. MFA alone is not a sufficient control when the attacker can capture and reuse the session as it is created.


At a glance

What this is: This is a threat-intelligence webinar summary about a five-month executive phishing campaign that bypassed MFA in real time and used a previously undocumented phishing-as-a-service platform.

Why it matters: It matters because IAM teams need to treat MFA as one control in a broader identity attack chain, especially where executives, session interception, and trusted account abuse are involved.


Context

Abnormal AI’s webinar focuses on a five-month phishing campaign that targeted named C-suite executives and used real-time authentication interception to turn a single login into persistent access. The subject is not generic phishing. It is the collapse of a login control when attackers can observe and reuse the session at the moment of authentication.

For IAM, PAM, and executive protection programmes, the practical issue is that MFA can be defeated without breaking the underlying account, especially when the attacker controls the timing and presentation of the login flow. The article also points to a previously undocumented phishing-as-a-service platform, which suggests a threat model built for repeatable scale rather than one-off operator tradecraft.


Key questions

Q: Why do MFA-protected executive accounts still get phished in real time?

A: Because MFA proves a user completed a challenge, not that the session was free from interception. When attackers relay the login as it happens, they can capture the authentication material, complete the session, and inherit the trusted context. For executives, that matters because the account’s authority often creates broader business and fraud exposure than the mailbox alone.

Q: What happens after an attacker gains access through session theft or MFA fatigue?

A: Once the attacker is inside, they can preserve access by adding new MFA devices, resetting passwords, and extending the hijack through social engineering. That often turns one compromised session into sustained account control. The practical consequence is delayed detection and broader damage unless the organization can terminate sessions, reset credentials, and investigate quickly.

Q: How should security teams reduce the risk of whaling phishing against executive accounts?

A: Security teams should combine strong email controls, multifactor authentication, and role-specific awareness training. Executive mailboxes and finance workflows need tighter verification for payment or data requests, especially when urgency is used to force action. Threat intelligence and automated triage help spot spoofed domains, suspicious attachments, and unusual message patterns before a malicious request reaches decision makers.

Q: What is the difference between stronger MFA and phishing-resistant authentication?

A: Stronger MFA usually means adding more factors, but phishing-resistant authentication changes the architecture so the factor cannot be easily replayed or proxied. FIDO2 is the clearest example because it binds authentication to the origin and keeps the private key on the device, which reduces interception risk.


Background and context

How real-time MFA interception defeats the login moment

Real-time MFA theft works by inserting the attacker into the authentication exchange while the user is still actively logging in. Instead of stealing a password for later reuse, the attacker captures one-time codes, approval signals, or session material fast enough to complete the authentication flow before the legitimate user realises what happened. That turns the login ceremony into a relay problem, not a credential-strength problem. The control failure is not the MFA factor itself, but the assumption that the factor proves the right person at the right moment. Once the attacker can proxy the session, the identity system may treat the hostile actor as authenticated.

Practical implication: teams need controls that inspect session creation and device trust, not just second-factor completion.

Why executive accounts become high-value launch points

Executive accounts are attractive because they are already trusted by internal recipients, finance processes, and downstream collaboration tools. Once compromised, they can be used to start business email compromise, request payment changes, or seed phishing from a legitimate-looking mailbox. That creates a privilege multiplier: the account itself may not hold elevated system rights, but it carries organizational authority and social trust. This is why identity risk is not only about technical permissions. It also includes who the account can persuade, whose workflows it can influence, and what approvals it can trigger without arousing suspicion.

Practical implication: classify executive identities as high-impact accounts and apply stronger monitoring, verification, and transaction controls.

How layered evasion weakens traditional detection

Layered evasion techniques are designed to break the assumptions of common email and web inspection. Unicode QR codes can evade text-based parsing, while URL fragments may remain invisible to server-side logs because they are handled in the browser. When those methods are combined with phishing kits or phishing-as-a-service infrastructure, defenders face both distribution scale and visibility gaps. That matters because detection built only on infrastructure reputation or mail gateway inspection misses the user-side execution path. The campaign described here shows how attacker tradecraft increasingly splits the attack across delivery, presentation, and authentication layers.

Practical implication: inspect the browser-side journey and user interaction path, not only mail or network indicators.


NHI Mgmt Group analysis

MFA interception is no longer a second-factor problem, it is a session-construction problem. When the attacker can proxy the login in real time, the security question shifts from whether MFA was used to whether the session was bound to the right context. That is a structural failure mode, not a simple control bypass. For identity teams, this means login completion is not a sufficient trust boundary.

Executive identity is a control surface, not just a user account. C-suite mailboxes, calendars, and messaging channels can steer payments, approvals, and internal trust at scale. This campaign shows that identity governance for executives must account for downstream organisational influence, not only authentication strength. The practitioner lesson is that high-trust identities need layered verification around sensitive requests, not only strong sign-in controls.

Real-time phishing-as-a-service compresses attacker skill and expands operational reach: a previously undocumented platform suggests repeatable tradecraft that can be reused across many campaigns. That changes the governance assumption that sophisticated executive phishing is rare or bespoke. The implication is that identity security programmes should treat this pattern as scalable infrastructure, not isolated criminal behaviour.

Session theft breaks the assumption that authentication proves durable intent. MFA was designed for a world where the factor confirms a user at sign-in and the resulting session remains trustworthy long enough to matter. That assumption fails when the attacker captures the session as it is created and uses it immediately. The implication is that practitioners must rethink where trust begins and ends in the access lifecycle.

The scale signal is as important as the technique signal. A five-month campaign targeting executives by name, combined with a phishing-as-a-service platform, points to repeatable monetisation rather than opportunistic abuse. That means defenders should map this threat to programme-level identity risk, not only to mail-security tuning. For practitioners, the right response is to treat executive phishing as an identity governance issue with fraud consequences.

What this signals

Real-time MFA interception should change how teams think about sign-in assurance. Access controls that stop at factor completion leave a gap when the attacker can ride the session at the moment it is created. Programme owners should assume that session trust is now as important as authentication success, especially for executives and finance users.

Executive identity protection now sits at the intersection of IAM and fraud prevention. A compromised C-suite mailbox can trigger payment diversion, internal impersonation, and wider phishing campaigns, so the control set must extend beyond authentication hygiene. The practical response is to align identity telemetry, mailbox governance, and business approval controls around high-impact accounts.

Phishing-as-a-service lowers the barrier to repeatable executive targeting. That means organisations should expect more campaigns built for scale, not fewer bespoke attacks. Security teams should harden the accounts that carry the most organisational trust and make sure browser-side and session-side telemetry are part of the detection strategy.


For practitioners

  • Harden executive account monitoring Apply enhanced alerting, mailbox rule review, and impossible-travel or anomalous-session detection to C-suite accounts and their delegated access paths.
  • Bind authentication to session context Use device posture, token binding, and conditional access policies that evaluate the session at issuance rather than accepting MFA completion as sufficient.
  • Add out-of-band verification for payment workflows Require separate approval channels for wire transfer changes, beneficiary updates, and other high-risk requests originating from executive mailboxes.
  • Inspect browser-side phishing indicators Augment gateway controls with user-side telemetry that can detect QR-based lures, invisible URL fragment abuse, and suspicious authentication relay behaviour.
  • Review phishing-resistant authentication for high-impact users Prioritise phishing-resistant methods for executives and finance staff where real-time interception makes one-time codes and push approvals fragile.

Key takeaways

  • This campaign shows that MFA can fail at the point of session creation when an attacker intercepts the login flow in real time.
  • Named executive targeting matters because compromised leadership accounts can be reused as trusted launchpads for fraud and internal phishing.
  • Identity teams should pair stronger authentication with session-aware monitoring and out-of-band verification for high-risk executive actions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centers on real-time MFA theft that defeats authentication assurance.
NHI-10 — Human Use of NHICompromised executive accounts are human identities abused as trusted launchpads.
Recommendation — Harden authentication flows so session issuance cannot be replayed through live interception. Restrict high-impact human accounts with stronger monitoring and approval controls.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe campaign relies on credential capture and trusted-account abuse for spread.
Recommendation — Map the campaign to credential access and lateral movement to prioritise detections around session theft.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article highlights the need to control authorizations around high-impact identities and sessions.
Recommendation — Review authorizations for executive accounts and tighten access conditions for sensitive actions.
OWASP API Security Top 10API2 — Broken AuthenticationThe login relay pattern is an authentication weakness even outside traditional API contexts.
Recommendation — Use broken-authentication thinking to test whether your login flow can resist relay attacks.

Key terms

  • Real-Time MFA Protection: Real-time MFA protection is the ability to challenge or block access as suspicious activity occurs, rather than after the fact. It extends verification to active sessions and internal resources so defenders can interrupt malicious logins, repeated push attempts, and unauthorized pivots before an attacker reaches broader parts of the environment.
  • Phishing-as-a-service: A criminal service model that packages phishing infrastructure, templates, delivery tools, and sometimes evasion features for reuse by multiple attackers. It lowers the skill threshold for advanced campaigns and makes targeted identity abuse more repeatable across victims and sectors.
  • High-impact account: A high-impact account is a registry or platform identity whose compromise can affect many downstream users, packages, or services. In package ecosystems, these accounts often control publication, ownership, or recovery paths, so abuse can quickly turn into supply chain exposure.
  • Runtime Trust: Runtime trust is the idea that access should remain valid only while current context justifies it. Instead of trusting a setup decision indefinitely, teams continuously re-evaluate whether a workload or agent still deserves privilege. This approach is especially important for AI agents that can change behaviour mid-task.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org