Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails
A phishing campaign using Adversary-in-the-Middle (AitM) techniques targets Microsoft 365 accounts to steal credentials and collect emails from payroll and finance personnel. The attack leverages residential proxies and legitimate services to bypass security measures, maintaining compromised sessions through automated activity.
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.
"The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,
*** END OF TRANSMISSION ***