Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Iran-aligned phishing, MFA theft and the governance gap teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 9016
Topic starter  

TL;DR: Iran-aligned threat groups are using email, real-time phishing kits, and compromised mailboxes to steal credentials, bypass standard MFA, and spread destructive access across cloud environments, according to Abnormal AI and multiple threat intelligence sources. The underlying problem is not just phishing volume but identity trust that still assumes human-paced review and revocation.

NHIMG editorial — based on content published by Abnormal AI: Iran-aligned phishing campaigns, MFA token theft, and inbox compromise patterns

By the numbers:

Questions worth separating out

Q: How should security teams handle phishing-resistant MFA for privileged accounts?

A: Security teams should prioritise phishing-resistant MFA for administrators, security operators, and executives before broad rollout elsewhere.

Q: Why do compromised mailboxes make internal phishing more effective?

A: A compromised mailbox converts an external threat into a trusted internal sender.

Q: What do organisations get wrong about MFA when attackers harvest tokens live?

A: They assume MFA always prevents account takeover.

Practitioner guidance

  • Move privileged users to phishing-resistant MFA first Replace TOTP and SMS for administrators, security staff, and executives with FIDO2 security keys or passkeys, then verify that recovery flows do not reintroduce replayable authentication.
  • Treat mailbox compromise as an identity incident Correlate suspicious outbound mail, unusual internal reply chains, and new sign-in events so a compromised inbox triggers identity containment, not only mail quarantine.
  • Review OAuth consents and MFA registrations after every alert Check for newly granted application consents, new authenticators, modified device registrations, and role changes in the identity provider whenever a credential event is suspected.

What's in the full article

Abnormal AI's full analysis covers the operational detail this post intentionally leaves for the source:

  • Direct descriptions of the phishing kit patterns used by Iran-aligned groups and how those lures are delivered
  • The specific defensive priorities Abnormal AI recommends for email, identity, and privileged access controls
  • Examples of conflict-themed lure content and the telemetry signals the vendor says it is monitoring
  • The integration guidance for Abnormal's security posture visibility into Microsoft Intune

👉 Read Abnormal AI's analysis of Iran-aligned phishing, MFA theft, and inbox compromise →

Iran-aligned phishing, MFA theft and the governance gap teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 8472
 

Email is now an identity enforcement point, not a side channel. When attackers use compromised inboxes to phish internally, email security and identity governance converge into the same control problem. The organisation is no longer defending only against malicious messages, but against legitimate identities being turned into attack infrastructure. Practitioners should treat mailbox compromise as a lifecycle and trust issue, not just a spam issue.

Credential trust debt: organisations should expect identity compromise to move faster than manual review cycles, because once one account is trusted internally, the attacker inherits that trust path across mail, cloud, and admin systems. The practical signal is simple: if your response process treats mailbox compromise separately from identity compromise, the programme is already behind.

A question worth separating out:

Q: Who is accountable when stolen credentials are reused for follow-on attacks?

A: Accountability sits with both the identity owner and the organisation's access governance process. If compromised accounts are not quickly contained, reviewed, and offboarded from risky entitlements, stolen credentials can be reused by the original actor or sold onward, creating secondary abuse that is preventable with lifecycle control.

👉 Read our full editorial: Iran-aligned phishing campaigns expose identity gaps in the inbox



   
ReplyQuote
Share: