Adversary-in-the-middle (AiTM) phishing has become the most common method for attackers to gain initial access to law firms, surpassing traditional credential theft. This shift occurs even as multifactor authentication (MFA) is widely adopted within the legal sector, yet frequently bypassed by sophisticated attack techniques, as reported by Infosecurity Magazine.A new report from eSentire reveals that AiTM attacks accounted for 28.57% of all initial access events in the legal sector, with a 20% year-over-year increase in incidents targeting these organizations. While credential and identity-focused threats remain significant at 56.3%, the nature of attacks has evolved. AiTM attacks work by proxying the authentication process, allowing attackers to steal valid session cookies even after a user completes an MFA challenge. The Tycoon2FA phishing-as-a-service platform was a major driver of these compromises.Additionally, ClickFix attacks, which exploit workflow pressures and fake error messages, have surged in the legal sector, often delivering NetSupportManager RAT. Microsoft Teams abuse and infostealers like Lumma Stealer are also prevalent. With an 86% overall intrusion ratio, attackers are prioritizing data and account access over operational disruption, favoring quiet infiltration. eSentire recommends phishing-resistant MFA, conditional access policies, and robust log monitoring, noting that only 34% of law firms have a formal incident response plan.Source: Infosecurity Magazine
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds





