Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
AI-summarised brief · reviewed before publication
Cybersecurity researchers identified a widespread adversary-in-the-middle phishing campaign targeting Microsoft 365 accounts to harvest payroll and finance emails. Arctic Wolf Labs reported the attack uses residential proxies to disguise malicious sign-ins as legitimate consumer traffic, impacting organizations in healthcare, education, manufacturing, government, and professional services across the U.S., Canada, and Europe. The campaign shares tactics with Microsoft’s tracked Storm-2755 and Storm-2657 threats. Attackers employ voicemail-themed emails leading to a six-stage redirection chain using trusted services like Google and Amazon S3 to bypass filters. This infrastructure captures credentials and multi-factor authentication codes while fingerprinting victim devices. Post-compromise, actors use geolocation data to select matching residential proxies, maintaining sessions via automated eight-hour intervals. They leverage the Microsoft Graph API to identify HR and finance personnel, subsequently accessing sensitive messages related to payroll and invoices to facilitate financial fraud.
💡 Why It Matters
- · The campaign’s sophisticated use of trusted infrastructure and geolocation-matched proxies bypasses standard security controls, allowing attackers to maintain persistent access to sensitive financial data.
- · This evolution in adversary-in-the-middle tactics demonstrates that traditional multi-factor authentication is insufficient against automated session hijacking, leaving organizations vulnerable to direct financial theft through compromised employee accounts.