• Sign in
  • Register

Lost your password?

A password will be sent to your email address.

Your personal data will be used to support your experience throughout this website, to manage access to your account, and for other purposes described in our privacy policy.

Close
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
Cyber Attack

Sophisticated VoidProxy Service Bypasses MFA to Steal Microsoft 365 and Google Credentials in Real-Time

ClickControl

Author

September 24, 2025

Published

# VoidProxy: New Phishing Platform Targets Microsoft 365 and Google Accounts

Cybersecurity researchers at Okta have uncovered a sophisticated new phishing-as-a-service (PhaaS) platform called VoidProxy that specifically targets Microsoft 365 and Google accounts, including those protected by third-party single sign-on (SSO) providers like Okta.

## How VoidProxy Works

VoidProxy employs adversary-in-the-middle (AitM) tactics to steal user credentials, multi-factor authentication (MFA) codes, and session cookies in real time. The platform is described as highly scalable, evasive, and sophisticated in its approach.

### The Attack Process

**Initial Contact**: Attacks begin with phishing emails sent from compromised accounts at legitimate email service providers, including Constant Contact, Active Campaign, and NotifyVisitors. These emails contain shortened links that redirect victims through multiple redirections to malicious phishing sites.

**Infrastructure**: The malicious sites are hosted on disposable, low-cost domains using extensions like .icu, .sbs, .cfd, .xyz, .top, and .home. These sites are protected by Cloudflare to hide their real IP addresses and add legitimacy.

**Filtering System**: Visitors first encounter a Cloudflare CAPTCHA challenge designed to filter out bots and increase the appearance of legitimacy. A Cloudflare Worker environment is used to filter traffic and load pages selectively.

**Targeted Phishing**: Selected targets receive pages that perfectly mimic Microsoft or Google login screens, while other visitors are redirected to generic “Welcome” pages that pose no threat.

### The Credential Theft Process

When victims enter their credentials into the phishing forms, VoidProxy’s AitM system proxies these requests to legitimate Google or Microsoft servers. For federated accounts using SSO providers like Okta, victims are redirected to second-stage phishing pages that impersonate Microsoft 365 or Google SSO flows.

The platform’s proxy server acts as an invisible middleman, relaying traffic between victims and legitimate services while capturing usernames, passwords, and MFA codes. When legitimate services issue session cookies, VoidProxy intercepts and copies them, making them immediately available to attackers through the platform’s admin panel.

## Protection and Recommendations

Notably, users enrolled in phishing-resistant authentication methods like Okta FastPass were protected from VoidProxy attacks and received warnings about potential account compromise.

### Security Recommendations

Okta researchers recommend several protective measures:

– **Restrict sensitive app access** to managed devices only
– **Implement risk-based access controls**
– **Use IP session binding** for administrative applications
– **Enforce re-authentication** for administrators attempting sensitive actions

## Key Takeaway

VoidProxy represents a significant evolution in phishing attacks, demonstrating how cybercriminals are developing increasingly sophisticated tools to bypass traditional security measures. Organizations must adopt comprehensive, multi-layered security approaches that include phishing-resistant authentication methods to protect against these advanced threats.

Keywords: VoidProxy phishing platform, Microsoft 365 phishing attacks, Google account security threats, phishing-as-a-service PhaaS, adversary-in-the-middle AitM attacks, multi-factor authentication MFA bypass

Share This Article
Tags: adversary-in-the-middle AitM attacks Google account security threats Microsoft 365 phishing attacks multi-factor authentication MFA bypass phishing-as-a-service PhaaS VoidProxy phishing platform
Previous Article Sophisticated FileFix Campaign Uses Fake
Next Article FBI Issues Urgent Alert Criminal
Curve Line
logo_white

601 Notre Dame E.
Montreal, Quebec, H2Y 0C2

Quick Links
  • Cybersecurity News
  • Video Guides
  • Shop
Company
  • Home
  • About us
  • Contact
  • Careers
  • Privacy Policy
Get In Touch

Montreal: +1-438-600-2288
Miami: +1-786-442-1805
Toll-Free: 1-877-654-9901

Linkedin Instagram Youtube

(C) Copyright 2023-2025 ClickControl IT MSP & Cybersecurity, All Rights Reserved.