Story perspectives
New Phishing Threat: VoidProxy Bypasses MFA for Account Theft
9/15/2025
29 6
1 of 1
Story summary
- Okta Threat Intelligence has identified VoidProxy, a phishing-as-a-service platform targeting Microsoft and Google accounts.
- It employs Adversary-in-the-Middle techniques to bypass multi-factor authentication (MFA) and steal login credentials.
- Attackers send phishing emails from compromised legitimate accounts, using deceptive links and fake login pages.
- The platform captures usernames, passwords, MFA codes, and session cookies for full account access.
- Okta recommends phishing-resistant authentication, restricted access to sensitive apps, and employee training to recognize phishing attempts.
