LIVE · cybersecurity feed
Live wire
phishing

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,

zeroday.news ·

Cybersecurity researchers have reported an active and widespread email-driven phishing campaign targeting Microsoft 365 accounts. This campaign leverages adversary-in-the-middle (AitM) techniques to compromise accounts, with the ultimate goal of identifying key personnel involved in financial workflows and exfiltrating related email communications. The observed activity indicates a focused effort to gain access to sensitive financial and payroll information within targeted organizations.

The core mechanism of this attack involves AitM phishing. In such a scenario, attackers position themselves between a user and a legitimate login page, effectively proxying the authentication process. This allows them to intercept credentials, including multi-factor authentication (MFA) tokens or session cookies, as they are exchanged. By capturing these elements, the attackers can then bypass MFA and establish their own authenticated session, thereby hijacking the legitimate user's account.

A notable characteristic of this particular campaign is its use of residential proxies. Attackers are routing their malicious sign-in attempts through these proxies, which makes the traffic appear to originate from ordinary consumer internet service provider (ISP) connections. This tactic helps to mask the true origin of the attacks and can make it more difficult for security systems to distinguish malicious login attempts from legitimate user activity, potentially allowing the attackers to evade detection mechanisms that flag unusual IP addresses or geographic locations.

Once an account is compromised, the attackers focus on reconnaissance within the victim's Microsoft 365 environment. Their objective is to identify individuals involved in payroll and finance operations. This often involves searching mailboxes for keywords, sender addresses, or specific types of attachments commonly associated with financial transactions, invoices, or payroll processing. The subsequent collection of related emails suggests an intent to either directly exfiltrate sensitive data or to prepare for further attacks, such as business email compromise (BEC) scams.

Microsoft 365 environments are frequently targeted due to their widespread adoption in business operations and the sensitive data they often contain, including email, documents, and collaboration tools. Organizations utilizing Microsoft 365 are advised to implement robust security measures. These typically include strong multi-factor authentication for all users, regular security awareness training to educate employees about phishing threats, and the deployment of advanced threat protection solutions that can detect and block sophisticated phishing attempts, including those employing AitM techniques.

Mitigation strategies for this class of attack generally involve a multi-layered approach. Beyond MFA and user education, organizations should ensure that email security gateways are configured to detect and quarantine phishing emails, especially those attempting to direct users to malicious login pages. Monitoring for unusual login patterns, such as logins from previously unseen IP addresses or rapid consecutive logins from different geographical locations, can also help identify compromised accounts. Furthermore, regular audits of mailbox rules and forwarding settings can detect unauthorized changes made by attackers to maintain persistence or exfiltrate data.

phishingfinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
data center technology

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

Several cybersecurity incidents are highlighted, including a ban on Chinese data center technology, a supply chain attack on QuickFox VPN, and a phishing breach at IEH Corporation. Additionally, AI-generated content may be impacting Apple's bug bounty program, and a North Carolina port experienced an attack, alongside broader targeting of Wall Street.

vulnerability

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again

ai

Irregular, firm behind AI hacking incidents, won't say if there were more

A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”

security

North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]

cloud

Unveiling good and bad behaviors on the Agentic Internet

Cloudflare is shifting bot mitigation from point-in-time Risk assessment to continuous Trust evaluation. Learn how new good and bad behaviors from bots and agents are assessed by our systems, including BotBase and Precursor — and try out our Precursor Trace simulation to see how your own cursor movements would be assessed as human or bot.

ai

Introducing Radar Researcher: An AI tool for exploring Internet data in plain language

Cloudflare Radar Researcher is a new AI-powered tool that lets you explore global Internet trends and traffic data using plain language. Built entirely on Cloudflare's Developer Platform, it turns natural language queries into real, interactive charts.