Cybersecurity researchers have reported an active and widespread email-driven phishing campaign targeting Microsoft 365 accounts. This campaign leverages adversary-in-the-middle (AitM) techniques to compromise accounts, with the ultimate goal of identifying key personnel involved in financial workflows and exfiltrating related email communications. The observed activity indicates a focused effort to gain access to sensitive financial and payroll information within targeted organizations.
The core mechanism of this attack involves AitM phishing. In such a scenario, attackers position themselves between a user and a legitimate login page, effectively proxying the authentication process. This allows them to intercept credentials, including multi-factor authentication (MFA) tokens or session cookies, as they are exchanged. By capturing these elements, the attackers can then bypass MFA and establish their own authenticated session, thereby hijacking the legitimate user's account.
A notable characteristic of this particular campaign is its use of residential proxies. Attackers are routing their malicious sign-in attempts through these proxies, which makes the traffic appear to originate from ordinary consumer internet service provider (ISP) connections. This tactic helps to mask the true origin of the attacks and can make it more difficult for security systems to distinguish malicious login attempts from legitimate user activity, potentially allowing the attackers to evade detection mechanisms that flag unusual IP addresses or geographic locations.
Once an account is compromised, the attackers focus on reconnaissance within the victim's Microsoft 365 environment. Their objective is to identify individuals involved in payroll and finance operations. This often involves searching mailboxes for keywords, sender addresses, or specific types of attachments commonly associated with financial transactions, invoices, or payroll processing. The subsequent collection of related emails suggests an intent to either directly exfiltrate sensitive data or to prepare for further attacks, such as business email compromise (BEC) scams.
Microsoft 365 environments are frequently targeted due to their widespread adoption in business operations and the sensitive data they often contain, including email, documents, and collaboration tools. Organizations utilizing Microsoft 365 are advised to implement robust security measures. These typically include strong multi-factor authentication for all users, regular security awareness training to educate employees about phishing threats, and the deployment of advanced threat protection solutions that can detect and block sophisticated phishing attempts, including those employing AitM techniques.
Mitigation strategies for this class of attack generally involve a multi-layered approach. Beyond MFA and user education, organizations should ensure that email security gateways are configured to detect and quarantine phishing emails, especially those attempting to direct users to malicious login pages. Monitoring for unusual login patterns, such as logins from previously unseen IP addresses or rapid consecutive logins from different geographical locations, can also help identify compromised accounts. Furthermore, regular audits of mailbox rules and forwarding settings can detect unauthorized changes made by attackers to maintain persistence or exfiltrate data.






