Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active phishing campaign that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.
Intelligence analysis by Llama

The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic, and automated activity maintains compromised sessions at approximately eight-hour intervals. The activity is assessed to impact organizations across healthcare, education, manufacturing, government, and professional services sectors located in the U.S., Canada, and Europe.
Imagine someone is sending fake emails that look like they're from Microsoft, but they're actually trying to steal people's passwords and access their emails. This is a type of phishing attack that's been happening a lot lately, and it's very sneaky because it uses real-looking emails to try to trick people into giving up their information.
Analysis
Phishing Campaign Overview
The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic. This allows the threat actors to maintain compromised sessions at approximately eight-hour intervals. The activity is assessed to impact organizations across healthcare, education, manufacturing, government, and professional services sectors located in the U.S., Canada, and Europe.
Attack Chain
The attack chain involves the use of voicemail-themed phishing emails to lead victims to AitM decoy pages that act as a proxy for the legitimate Microsoft account authentication flow. The pages capture the victims' credentials and multi-factor authentication (MFA) codes. This is accomplished by means of a six-stage redirection chain that employs legitimate and trusted services like Google, Google Meet, Google Ads, and Amazon S3 to sidestep reputation-driven filters.
Phishing Pages
The phishing pages also employ JavaScript to fingerprint the visiting host, gathering information about the web browser, operating system, screen and window dimensions, browser language, time zone offset, cookie capabilities, WebDriver status, WebGL vendor, and browser API availability. All this information is packaged and sent to a PHP endpoint through an HTTP POST request.
Initial Access
Once initial access is obtained, the threat actor abuses the compromised sessions to collect emails from payroll and HR personnel who are involved in financial matters at the enterprise. The threat actors also use the compromised sessions to collect emails from payroll and HR personnel who are involved in financial matters at the enterprise.
Key points
- The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic.
- Automated activity maintains compromised sessions at approximately eight-hour intervals.
- The activity is assessed to impact organizations across healthcare, education, manufacturing, government, and professional services sectors located in the U.S., Canada, and Europe.
- The threat actors use a six-stage redirection chain to sidestep reputation-driven filters.
- The phishing pages employ JavaScript to fingerprint the visiting host and gather information about the web browser, operating system, and other details.
If this development plays out positively, it's possible that Microsoft will be able to implement new security measures to prevent this type of phishing attack from happening in the future. This could include new features that detect and block suspicious activity, as well as better education for users on how to spot and avoid phishing emails.
On the other hand, if this development plays out negatively, it's possible that the threat actors will continue to find new ways to evade security measures and steal people's information. This could lead to a wider spread of phishing attacks and a greater risk of identity theft and financial loss.



