discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active phishing campaign that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.

By Ravie Lakshmanan·Aug 7·thehackernews.com·2 min read

Intelligence analysis by Llama

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Image: thehackernews.com

The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic, and automated activity maintains compromised sessions at approximately eight-hour intervals. The activity is assessed to impact organizations across healthcare, education, manufacturing, government, and professional services sectors located in the U.S., Canada, and Europe.

Why it matters

This story matters to someone following Security because it highlights a widespread email-driven phishing campaign that employs AitM techniques to take control of Microsoft 365 accounts, with an aim to identify key personnel involved in financial workflows and gather related email.

Imagine someone is sending fake emails that look like they're from Microsoft, but they're actually trying to steal people's passwords and access their emails. This is a type of phishing attack that's been happening a lot lately, and it's very sneaky because it uses real-looking emails to try to trick people into giving up their information.

Analysis

Phishing Campaign Overview

The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic. This allows the threat actors to maintain compromised sessions at approximately eight-hour intervals. The activity is assessed to impact organizations across healthcare, education, manufacturing, government, and professional services sectors located in the U.S., Canada, and Europe.

Attack Chain

The attack chain involves the use of voicemail-themed phishing emails to lead victims to AitM decoy pages that act as a proxy for the legitimate Microsoft account authentication flow. The pages capture the victims' credentials and multi-factor authentication (MFA) codes. This is accomplished by means of a six-stage redirection chain that employs legitimate and trusted services like Google, Google Meet, Google Ads, and Amazon S3 to sidestep reputation-driven filters.

Phishing Pages

The phishing pages also employ JavaScript to fingerprint the visiting host, gathering information about the web browser, operating system, screen and window dimensions, browser language, time zone offset, cookie capabilities, WebDriver status, WebGL vendor, and browser API availability. All this information is packaged and sent to a PHP endpoint through an HTTP POST request.

Initial Access

Once initial access is obtained, the threat actor abuses the compromised sessions to collect emails from payroll and HR personnel who are involved in financial matters at the enterprise. The threat actors also use the compromised sessions to collect emails from payroll and HR personnel who are involved in financial matters at the enterprise.

Key points

  • The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic.
  • Automated activity maintains compromised sessions at approximately eight-hour intervals.
  • The activity is assessed to impact organizations across healthcare, education, manufacturing, government, and professional services sectors located in the U.S., Canada, and Europe.
  • The threat actors use a six-stage redirection chain to sidestep reputation-driven filters.
  • The phishing pages employ JavaScript to fingerprint the visiting host and gather information about the web browser, operating system, and other details.
The Upside

If this development plays out positively, it's possible that Microsoft will be able to implement new security measures to prevent this type of phishing attack from happening in the future. This could include new features that detect and block suspicious activity, as well as better education for users on how to spot and avoid phishing emails.

The Downside

On the other hand, if this development plays out negatively, it's possible that the threat actors will continue to find new ways to evade security measures and steal people's information. This could lead to a wider spread of phishing attacks and a greater risk of identity theft and financial loss.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsphishingemail-securitycybersecuritymicrosoft-365aitmresidential-proxiesautomated-activitycompromised-sessions

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Aug 7, 2026

Source

thehackernews.com

Share

Topics

phishingemail-securitycybersecuritymicrosoft-365aitmresidential-proxiesautomated-activitycompromised-sessions

Related

More from this desk

Aug 7·bleepingcomputer.com

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co. says hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that it…

Aug 7·bleepingcomputer.com

Real emails, hijacked payments: Two H1 2026 attack chains

Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings, and blockchain data as part of the attack path. The campaigns targeted users in Czechia, Slovakia, Poland, and Lithuania, using normal business emails with attachmen…

Aug 7·bleepingcomputer.com

North Carolina Ports confirms cyberattack disrupting operations

North Carolina Ports confirms cyberattack causing disruptions at three facilities.

Aug 7·thehackernews.com

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. The flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with …