
Cookie Heist: AiTM Session Theft to Payment-Fraud BEC
An adversary-in-the-middle phishing intrusion that turns into payment fraud without any malware. A voicemail-themed email with an HTML attachment routes a finance analyst through a redirector to an Evilginx2 proxy, which relays her real Microsoft 365 sign-in and steals the post-MFA session cookie. The attacker replays the cookie from a foreign hosting IP, bypassing MFA, then reads her mailbox, creates an email-hiding inbox rule keyed on a vendor's domain, deletes the phishing mail, and replies inside a live invoice thread asking the vendor to wire payment to a new account. Work the Entra sign-in audit, the Exchange Online mailbox operations, and the email evidence to reconstruct the chain.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Incident brief
0Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.
Locate the compromised identity
35One cloud account signed in twice within minutes, once normally and once from abroad. Identify the account that was taken over.
Pin the cookie-replay source
35The MFA bypass came from reusing a stolen session, not a password. Identify the external IP that replayed the session cookie.
Find the email-hiding inbox rule
35The attacker hid the vendor's replies so the fraud could proceed. Identify the sender domain the malicious inbox rule keys on.
Recover the fraudulent account details
30The attacker's end goal was a redirected wire. Identify the IBAN inserted into the vendor invoice thread.
Classify the MFA-bypass technique
35Name how the attacker defeated MFA. Map the stolen, replayed session to its MITRE ATT&CK technique.
Classify the email-hiding technique
35Name what the inbox rule was for. Map the rule that buries the vendor's replies to its MITRE ATT&CK technique.
7 tasks · 205 points total
Training Tools
Email Console
Email header & content analysis
SIEM Console
Log analysis & SPL queries
Cloud Console
Cloud infrastructure logs
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with Email concepts
- Familiarity with SIEM concepts
- Familiarity with Cloud concepts
Ready to investigate?
More Operations
View allDocker Hub Supply Chain: A Public Image on a Shared Build Runner
A platform engineer pulls a public Docker Hub image advertised as a network scanning utility onto a shared Linux build-runner. Hours later the host is still pinned at full CPU with its build queue drained, nothing deployed and no data alarms raised. Reconstruct what the image actually did on the host from endpoint XDR and perimeter firewall telemetry, and classify the key ATT&CK techniques.
GoldPickaxe: The First iOS Trojan Stealing Your Face
A mobile-first intrusion against a retail bank's managed iPhone fleet. A relationship officer is socially engineered into installing a fake government app through Apple TestFlight and trusting a rogue MDM profile, handing GoldFactory full control of the device. The GoldPickaxe.iOS trojan harvests identity documents and a facial-recognition video, intercepts SMS, and exfiltrates over three split channels: an RSA-encrypted HTTP API, a WebSocket command channel, and an RTMP face-video stream, all to enable AI face-swap fraud against the bank's facial verification. Reconstruct the chain from mobile-threat-defense, MDM, and perimeter firewall telemetry.
Trusted Tool, Hostile Hands: Atera RMM Foothold
A phishing-delivered intrusion that weaponized a legitimate remote-monitoring tool instead of custom malware. A finance analyst was lured by a grant-program email whose link pointed at a file-sharing platform; the download was an MSI that silently installed the Atera agent, registered the endpoint to an attacker-controlled tenant, persisted as a Windows service, and beaconed to Atera's cloud over HTTPS. From the vendor console the operator ran PowerShell discovery and staged a follow-on implant, all over trusted infrastructure. Reconstruct the chain from email, SIEM, and endpoint XDR telemetry and classify the key ATT&CK techniques.