VoidProxy phishing service targets Microsoft 365 and Google accounts
Summary
Hide ▲
Show ▼
A new phishing-as-a-service (PhaaS) platform, VoidProxy, targets Microsoft 365 and Google accounts, including those protected by third-party single sign-on (SSO) providers such as Okta. The platform uses adversary-in-the-middle (AitM) tactics to steal credentials, multi-factor authentication (MFA) codes, and session cookies in real time. The attack begins with emails from compromised accounts at email service providers, which include shortened links redirecting recipients to phishing sites. The phishing sites are hosted on disposable low-cost domains protected by Cloudflare. The attack flow involves multiple redirections, CAPTCHA challenges, and traffic filtering to evade detection and increase legitimacy. Selected targets are served phishing pages mimicking Microsoft or Google login, while others receive a generic welcome page. Credentials entered into the phishing form are proxied through VoidProxy’s AitM to the legitimate service’s servers, capturing usernames, passwords, and MFA codes. Session cookies issued by the legitimate service are intercepted and made available to the attackers. Okta noted that users enrolled in phishing-resistant authentications like Okta FastPass were protected from VoidProxy’s attack flow and received warnings about their account being under attack.
Timeline
-
14.09.2025 17:23 📰 1 articles · ⏱ 1d ago
VoidProxy phishing service targets Microsoft 365 and Google accounts
A new phishing-as-a-service (PhaaS) platform, VoidProxy, targets Microsoft 365 and Google accounts, including those protected by third-party single sign-on (SSO) providers such as Okta. The platform uses adversary-in-the-middle (AitM) tactics to steal credentials, multi-factor authentication (MFA) codes, and session cookies in real time. The attack begins with emails from compromised accounts at email service providers, which include shortened links redirecting recipients to phishing sites. The phishing sites are hosted on disposable low-cost domains protected by Cloudflare. The attack flow involves multiple redirections, CAPTCHA challenges, and traffic filtering to evade detection and increase legitimacy. Selected targets are served phishing pages mimicking Microsoft or Google login, while others receive a generic welcome page. Credentials entered into the phishing form are proxied through VoidProxy’s AitM to the legitimate service’s servers, capturing usernames, passwords, and MFA codes. Session cookies issued by the legitimate service are intercepted and made available to the attackers. Users enrolled in phishing-resistant authentications like Okta FastPass were protected from VoidProxy’s attack flow and received warnings about their account being under attack.
Show sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
Information Snippets
-
VoidProxy is a new phishing-as-a-service (PhaaS) platform targeting Microsoft 365 and Google accounts.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
-
The platform uses adversary-in-the-middle (AitM) tactics to steal credentials, MFA codes, and session cookies in real time.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
-
The attack begins with emails from compromised accounts at email service providers, including Constant Contact, Active Campaign, and NotifyVisitors.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
-
The phishing sites are hosted on disposable low-cost domains on .icu, .sbs, .cfd, .xyz, .top, and .home, protected by Cloudflare.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
-
The attack flow involves multiple redirections, CAPTCHA challenges, and traffic filtering to evade detection and increase legitimacy.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
-
Selected targets are served phishing pages mimicking Microsoft or Google login, while others receive a generic welcome page.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
-
Credentials entered into the phishing form are proxied through VoidProxy’s AitM to the legitimate service’s servers, capturing usernames, passwords, and MFA codes.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
-
Session cookies issued by the legitimate service are intercepted and made available to the attackers.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
-
Users enrolled in phishing-resistant authentications like Okta FastPass were protected from VoidProxy’s attack flow and received warnings about their account being under attack.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23
-
Okta recommends restricting access of sensitive apps only to managed devices, enforcing risk-based access controls, using IP session binding for administrative apps, and forcing re-authentication for admins attempting sensitive actions.
First reported: 14.09.2025 17:23📰 1 source, 1 articleShow sources
- New VoidProxy phishing service targets Microsoft 365, Google accounts — www.bleepingcomputer.com — 14.09.2025 17:23