Technology News

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Adversary‑in‑the‑middle attacks target financial workflows in Office 365

A new phishing attack uses adversary‑in‑the‑middle and residential proxies to hijack Microsoft 365 accounts and harvest payroll and finance emails.

A new phishing campaign has been uncovered that targets Microsoft 365 accounts using adversary‑in‑the‑middle (AitM) techniques, allowing attackers to hijack user sessions and harvest sensitive payroll and finance emails.

Researchers have identified the campaign as email‑driven, with spear‑phishing messages that lure employees into clicking malicious links or opening attachments that install credential‑stealing malware.

Once credentials are compromised, the attackers use residential proxies to mask their traffic as ordinary consumer activity, which helps them evade IP‑based blocking and detection by Microsoft’s security tools.

The AitM component allows the attackers to intercept authentication flows and replace tokens, effectively bypassing multi‑factor authentication and gaining full access to the victim’s mailbox.

With full mailbox access, the attackers sift through financial workflows, targeting key personnel such as finance managers, payroll administrators, and CFOs, and then copy or forward payroll and finance‑related emails to their own accounts.

The stolen emails can then be used to launch further attacks, including credential stuffing, social‑engineering, or to create a foothold for ransomware or data‑exfiltration.

Microsoft has issued guidance urging users to enable MFA, monitor for unusual sign‑in patterns, and to use conditional access policies that flag sign‑ins from residential IP ranges.

Security teams should also review mailbox audit logs for signs of AitM activity, such as repeated authentication requests from the same user that are answered by a different IP address, and to block or quarantine any traffic that originates from known residential proxy services.

The use of residential proxies is a key element of the campaign, as it allows attackers to blend in with legitimate traffic and remain undetected for longer periods, giving them the bandwidth to harvest large volumes of sensitive data.

In short, the campaign demonstrates a sophisticated blend of phishing, AitM, and residential proxy techniques that together allow attackers to hijack Microsoft 365 accounts and harvest payroll and finance emails, posing a serious threat to organizations reliant on Office 365 for financial operations.

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

A new phishing campaign has been uncovered that targets Microsoft 365 ac…

A new phishing campaign has been uncovered that targets Microsoft 365 ac…

A new phishing campaign has been uncovered that targets Microsoft 365 accounts using adversary‑in‑the‑middle (AitM) techniques, allowing attackers to hijack user sessions and harvest sensitive payroll and finance emails.

Researchers have identified the campaign as email‑driven, with spear‑phishing messages that lure employees into clicking malicious links or opening attachments that install credential‑stealing malware.

Once credentials are compromised, the attackers use residential proxies…

Once credentials are compromised, the attackers use residential proxies…

Once credentials are compromised, the attackers use residential proxies to mask their traffic as ordinary consumer activity, which helps them evade IP‑based blocking and detection by Microsoft’s security tools.

The AitM component allows the attackers to intercept authentication flows and replace tokens, effectively bypassing multi‑factor authentication and gaining full access to the victim’s mailbox.

With full mailbox access, the attackers sift through financial workflows…

With full mailbox access, the attackers sift through financial workflows…

With full mailbox access, the attackers sift through financial workflows, targeting key personnel such as finance managers, payroll administrators, and CFOs, and then copy or forward payroll and finance‑related emails to their own accounts.

The stolen emails can then be used to launch further attacks, including credential stuffing, social‑engineering, or to create a foothold for ransomware or data‑exfiltration.

Microsoft has issued guidance urging users to enable MFA, monitor for un…

Microsoft has issued guidance urging users to enable MFA, monitor for un…

Microsoft has issued guidance urging users to enable MFA, monitor for unusual sign‑in patterns, and to use conditional access policies that flag sign‑ins from residential IP ranges.

Security teams should also review mailbox audit logs for signs of AitM activity, such as repeated authentication requests from the same user that are answered by a different IP address, and to block or quarantine any traffic that originates from known residential proxy services.

The use of residential proxies is a key element of the campaign, as it a…

The use of residential proxies is a key element of the campaign, as it a…

The use of residential proxies is a key element of the campaign, as it allows attackers to blend in with legitimate traffic and remain undetected for longer periods, giving them the bandwidth to harvest large volumes of sensitive data.

In short, the campaign demonstrates a sophisticated blend of phishing, AitM, and residential proxy techniques that together allow attackers to hijack Microsoft 365 accounts and harvest payroll and finance emails, posing a serious threat to organizations reliant on Office 365 for financial operations.