Ethical Hacking News
A recent Microsoft 365 AitM phishing campaign has been detected, compromising accounts to collect payroll and finance emails. The attackers use residential proxies to disguise malicious sign-ins and maintain stolen sessions through automated activity. Organizations are advised to stay vigilant against email security threats and take proactive measures to protect their systems and data.
A widespread email-driven phishing campaign has been detected, targeting key personnel involved in financial workflows using sophisticated AitM techniques to compromise Microsoft 365 accounts.The attackers are using residential proxies to disguise malicious sign-ins and bypass reputation-driven filters, employing a six-stage redirection chain to capture credentials and MFA codes.Arctic Wolf observed hundreds of organizations targeted by email as part of this phishing campaign, resulting in successful intrusions across various victim environments.The attackers are restricting their post-compromise actions to session maintenance, reconnaissance, and mailbox collection, avoiding common BEC behaviors for early detection evasion.The phishing campaign utilizes rotating residential proxies to maintain stolen sessions, identify personnel involved in financial workflows, and collect relevant mailbox data through automated activity.
Threat Intelligence Community Notifies Widespread Email-Driven Phishing Campaign Hijacking Microsoft 365 Accounts to Obtain Payroll and Finance Emails
A recent phishing campaign has been detected, employing sophisticated adversary-in-the-middle (AitM) techniques to compromise Microsoft 365 accounts. This email-driven campaign is specifically targeting key personnel involved in financial workflows and gathering related emails from payroll and HR departments.
According to Arctic Wolf Labs, the attackers are using residential proxies to disguise malicious sign-ins as ordinary consumer traffic. The attack chain involves a series of redirects that use legitimate services such as Google, Google Meet, Google Ads, and Amazon S3 to bypass reputation-driven filters.
A six-stage redirection chain employing these trusted services allows for stealthy capture of credentials and multi-factor authentication (MFA) codes. Once the attackers gain access, they maintain stolen sessions, identify personnel involved in financial workflows, and collect relevant mailbox data through automated activity.
Arctic Wolf observed hundreds of organizations being targeted by email as part of this phishing campaign last month, resulting in successful intrusions spanning a broad range of victim environments. The threat actors have been found relying on the Microsoft Graph API to enumerate tenant users associated with payroll, HR, finance, and administrative functions, then accessing messages related to payroll, invoices, payments, banking, benefits, and internal documents.
The attackers are restricting their post-compromise actions to session maintenance, reconnaissance, and mailbox collection. They avoid common Business Email Compromise (BEC) behaviors such as account modification or outbound email abuse, making early detection challenging. However, some cases involve the attackers engaging in hands-on keyboard activity to create inbox rules that automatically move certain messages from Inbox to Deleted Items and mark them as read.
This phishing campaign utilizes rotating residential proxies to quietly maintain stolen sessions, identify personnel involved in financial workflows, and collect relevant mailbox data through automated activity. The delay between initial access and subsequent automation, combined with restrained post-compromise activity, makes the campaign harder to connect to the original phishing event and less likely to trigger existing detections.
This new threat highlights the importance of staying vigilant against email security threats and maintaining robust defenses against phishing campaigns. As cybersecurity threats continue to evolve, it is essential for organizations to stay informed about the latest attacks and take proactive measures to protect their systems and data.
Related Information:
https://www.ethicalhackingnews.com/articles/New-Microsoft-365-AitM-Phishing-Campaign-Hijacks-Accounts-to-Collect-Payroll-and-Finance-Emails-ehn.shtml
https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html
Published: Fri Aug 7 06:38:29 2026 by llama3.2 3B Q4_K_M