Join our Newsletter — 33% off our NHI Course

Executive phishing and MFA interception: what IAM teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: A five-month campaign targeted C-suite executives by name, used a previously undocumented phishing-as-a-service platform called VENOM, and combined evasion tactics with real-time authentication interception to turn a single login into persistent account access, according to Abnormal AI. MFA alone is not a sufficient control when the attacker can capture and reuse the session as it is created.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Exposing VENOM: PhaaS Platform Targeting C-Suite Credentials”.

Key questions

Q: Why do MFA-protected executive accounts still get phished in real time?

A: Because MFA proves a user completed a challenge, not that the session was free from interception.

Q: What happens after an attacker gains access through session theft or MFA fatigue?

A: Once the attacker is inside, they can preserve access by adding new MFA devices, resetting passwords, and extending the hijack through social engineering.

Practitioner guidance

  • Harden executive account monitoring Apply enhanced alerting, mailbox rule review, and impossible-travel or anomalous-session detection to C-suite accounts and their delegated access paths.
  • Bind authentication to session context Use device posture, token binding, and conditional access policies that evaluate the session at issuance rather than accepting MFA completion as sufficient.
  • Add out-of-band verification for payment workflows Require separate approval channels for wire transfer changes, beneficiary updates, and other high-risk requests originating from executive mailboxes.

Bottom line: This campaign shows that MFA can fail at the point of session creation when an attacker intercepts the login flow in real time.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21474
 

MFA interception is no longer a second-factor problem, it is a session-construction problem. When the attacker can proxy the login in real time, the security question shifts from whether MFA was used to whether the session was bound to the right context. That is a structural failure mode, not a simple control bypass. For identity teams, this means login completion is not a sufficient trust boundary.

A question worth separating out:

Q: What is the difference between stronger MFA and phishing-resistant authentication?

A: Stronger MFA usually means adding more factors, but phishing-resistant authentication changes the architecture so the factor cannot be easily replayed or proxied. FIDO2 is the clearest example because it binds authentication to the origin and keeps the private key on the device, which reduces interception risk.

👉 Read our full editorial: Phishing-as-a-service and real-time MFA theft target executives


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.