
Scinary Information Nexus
Episode 60: Cloud Persistence: Rogue MFA, OAuth and Passkeys
Welcome back to the Scinary Information Nexus! This week, the crew had to toss their planned agenda out the window. Richard, Joseph, Mario, and Brazos jump in for an emergency breakdown of an aggressive phishing wave battering K-12 school districts and higher ed institutions. Attackers are weaponizing legitimate Google Docs and using Adversary-in-the-Middle (AiTM) proxies to harvest credentials and bypass traditional MFA. Because the phishing notifications originate straight from Google's own servers, they breeze past standard SPF, DKIM, and DMARC checks. Once inside, threat actors hijack internal distribution lists to spread laterally, creating a virtual denial of service for IT teams through sheer operational attrition. Even worse, standard password resets aren't cutting it. Attackers are locking in persistent cloud access with rogue OAuth application grants, hidden MFA enrollments, and rogue device keys. We break down how this campaign works, examine the CAPTCHA fatigue driving users straight toward ClickFix social engineering lures, and share concrete hardening tactics you can implement inside Google Admin right now to lock down your domain. In this episode: Anatomy of the breach: How weaponized Google Docs bypass email authentication filters. AiTM in action: Why traditional MFA fails against adversary-in-the-middle session theft. Cloud persistence traps: How rogue OAuth permissions and device keys survive password resets. Denial of service by attrition: The hidden toll of high-velocity account takeovers on IT teams. CAPTCHA fatigue: How flagged outbound IPs prime users for ClickFix social engineering. Hardening Google Admin: Disabling student directory lookups and ditching formulaic passwords. The Google Workspace dilemma: Free EDU tiers and gated security features. Has your organization noticed a spike in AiTM phishing or Google Docs lures lately? Let us know in the comments how your team is responding! Connect with Us: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 01:45 Google Docs Phishing & AiTM MFA Bypass 07:00 Cloud Persistence: Rogue OAuth & Device Keys 11:45 IT Attrition & CAPTCHA Fatigue Risks 21:15 Hardening Google Admin & Zero Trust 33:45 Google Ecosystem & Prompt Injections Cybersecurity #InfoSec #Phishing

