Drooid Logo
Back to today’s briefing

Story perspectives

New Phishing Threat: VoidProxy Bypasses MFA for Account Theft

9/15/2025

29 6

1 of 1

Story summary
  • Okta Threat Intelligence has identified VoidProxy, a phishing-as-a-service platform targeting Microsoft and Google accounts.
  • It employs Adversary-in-the-Middle techniques to bypass multi-factor authentication (MFA) and steal login credentials.
  • Attackers send phishing emails from compromised legitimate accounts, using deceptive links and fake login pages.
  • The platform captures usernames, passwords, MFA codes, and session cookies for full account access.
  • Okta recommends phishing-resistant authentication, restricted access to sensitive apps, and employee training to recognize phishing attempts.