CypherCon 2026
Papa! Mama! Watch me campaign in the cloud!
Anna Akselevich & Yaniv Miron
Abstract:
This talk presents findings from multiple real-world Account Takeover (ATO) campaigns observed across our global telemetry and enriched by uniquely large-scale forensic datasets unavailable to most organizations. This visibility allows us to measure attacker behavior, campaign impact, and emerging trends with uncommon precision. We open with the first public reveal of our new cloud-campaign analysis tool, built to map, classify, and quantify ATO activity across cloud environments.
We begin by outlining what attackers gain from these campaigns: financial profit, long-term access, identity control, data exfiltration, and the power to pivot into broader organizational compromise. This framing sets the stage for three case studies.
The first case study covers session hijacking and adversary-in-the-middle (AiTM) techniques used to bypass MFA. The second examines refined brute-force and password-spray operations. The third explores malicious OAuth application abuse that grants attackers persistent, credential-less access. For each, we present statistics derived from our data and show the real-world impact on affected organizations.
We then introduce the IoC Annalyzer, our framework for correlating campaign IoCs with Azure sign-in logs to uncover cross-campaign patterns and quantify business impact. We also discuss how attackers are integrating AI to automate login attempts, mimic user behavior, and accelerate access and exfiltration at scale.
Finally, the Full Flow section reconstructs a modern end-to-end ATO campaign, demonstrating how attackers chain together session hijacking, brute force, OAuth abuse, automation, and social engineering into a unified attack flow.

Anna Akselevich

Yaniv Miron
Forensic datasets active!
Anna Akselevich – Proofpoint’s Cloud Threat Researcher, with a background in intelligence,
cyber operations, building automations for research purposes. Over the past 8 years, she
has focused on researching cloud-based attack campaigns and threat actor infrastructure.
She holds experience in public speaking, threat reporting, translating complex attack
patterns into practical insights and publishing technical blogs.
Yaniv Miron – Cloud Threat Research Manager at Proofpoint
With a lifelong passion for cybersecurity, Mr. Miron has spent years working as a security consultant and researcher.
He holds multiple certifications, including CISO, CEPT, CREA, CSSA and Exploit Development.
Mr. Miron has discovered multiple 0-day vulnerabilities in Microsoft, Oracle, and other major vendors’ products, and have reported and credited for these issues.
He is a recognized global speaker at leading cybersecurity and hacking conferences such as Black Hat, HackFest, Power of Community, CONFidence, IL.Hack, and Hacker Halted.
In addition to his technical expertise, Mr. Miron is an entrepreneur and inventor.