hacker-news · Crawled Aug 7, 2026

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

1 IoCs
Read original article ↗

AI Summary

An active, widespread phishing campaign is targeting Microsoft 365 users using adversary-in-the-middle (AitM) techniques to hijack accounts and collect payroll and finance-related emails. The attack chain begins with voicemail-themed phishing emails that redirect through legitimate services like Google and Amazon S3 to mask malicious infrastructure. The AitM pages capture credentials and MFA codes, while JavaScript fingerprints the victim's browser and sends data to a PHP endpoint. Attackers use residential proxies to maintain long-lived, geographically proxied sessions and abuse Microsoft Graph API to enumerate and collect sensitive mailbox data, avoiding typical BEC behaviors to evade detection.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain api[.]country[.]is Details →