Yasuo Atobe square

Yasuo Atobe

Engineer, Varonis

Yasuo Atobe is an IT Security Professional with 20+ years background in IT industry. He has worked on such solutions as networking, server hosting, cloud content delivery, content monitoring and filtering, encryption, cloud security. He dedicates his efforts to make society allow people freely access, communicate and share information, no matter how far apart they are, without fear of security nor language barrier.

Here’s an outline of how the attack works:

  • We trick a user into entering creds into our fake O365 login page (made with evilginx)
  • We make Microsoft send a passcode to the user’s phone
  • User enters their passcode on OUR fake page
  • We hijack the user’s session token
  • Gain access to SharePoint Online environment
  • Exfiltrate data from O365
  • Pivot to on-prem and steal CEO’s emails (because why not?)
Our Clients