Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

August 7, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations in healthcare, education, manufacturing, government, and professional services
Incident: Adversary-in-the-Middle (AitM) phishing campaign targeting Microsoft 365 accounts.
Impact: Unauthorized access to corporate mailboxes and theft of sensitive financial workflow data.
Attacker: Payroll Pirates (Storm-2755/Storm-2657)
Analysis: This campaign leverages a complex redirection chain involving trusted services like Google and Amazon S3 to evade reputation filters. By deploying residential proxies and AitM proxy pages, attackers can bypass multi-factor authentication (MFA) and maintain stealthy, automated sessions. The primary goal is the identification and exploitation of personnel involved in financial and payroll workflows.
Recommendations: Implement FIDO2-compliant phishing-resistant MFA to prevent session hijacking; Deploy strict conditional access policies that require compliant, managed devices; Educate employees to be wary of voicemail-themed lures and unexpected redirection chains
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *