Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
AI Summary
An active, widespread phishing campaign is targeting Microsoft 365 users using adversary-in-the-middle (AitM) techniques to hijack accounts and collect payroll and finance-related emails. The attack chain begins with voicemail-themed phishing emails that redirect through legitimate services like Google and Amazon S3 to mask malicious infrastructure. The AitM pages capture credentials and MFA codes, while JavaScript fingerprints the victim's browser and sends data to a PHP endpoint. Attackers use residential proxies to maintain long-lived, geographically proxied sessions and abuse Microsoft Graph API to enumerate and collect sensitive mailbox data, avoiding typical BEC behaviors to evade detection.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | api[.]country[.]is | Details → |