Cybersecurity researchers have issued a warning regarding an active and widespread email-driven phishing campaign designed to compromise Microsoft 365 accounts. The operation utilizes adversary-in-the-middle (AitM) techniques to bypass traditional security measures, allowing attackers to intercept authentication tokens and gain unauthorized access to corporate environments. The primary objective of the threat actors appears to be the identification of key personnel involved in financial workflows to gather sensitive payroll and finance-related email communications.
To evade detection by security monitoring systems, the campaign employs residential proxies to disguise malicious sign-in attempts. By routing traffic through these proxies, the attackers make their unauthorized access attempts appear as ordinary consumer traffic, complicating the ability of automated systems to flag the activity as anomalous. This method effectively masks the geographical location and reputation of the source IPs used in the hijacking process.
Once access is established, the attackers conduct internal reconnaissance to locate high-value targets within the organization's finance and payroll departments. The collection of specific financial emails suggests a targeted approach aimed at understanding or disrupting internal monetary processes. This ongoing activity highlights a sophisticated shift in how phishing campaigns are structured to maintain persistence and bypass multi-factor authentication protocols.
For CIOs, IT directors, and operations leaders, this development emphasizes the evolving nature of AitM threats against standard enterprise cloud platforms. Understanding the use of residential proxies to hide malicious traffic is critical for teams managing Microsoft 365 environments and overseeing internal financial data security. Monitoring for these specific tactics is necessary to mitigate the risk of account takeovers and subsequent data exfiltration.
The BroadVision view
Adversary-in-the-middle attacks bypass traditional multi-factor authentication by intercepting session tokens through proxy servers. For mid-market IT teams, this shift necessitates the implementation of phishing-resistant authentication methods and the continuous monitoring of sign-in logs for anomalous residential IP addresses. Establishing rigorous access controls and session management protocols helps mitigate the risk of account hijacking. Learn about strategic IT services
