Cybersecurity experts are raising alarms over a significant phishing campaign deploying adversary-in-the-middle (AitM) tactics to breach Microsoft 365 accounts. The primary target is individuals involved in financial operations to access their emails and pertinent data.
Residential Proxies Mask Malicious Activity
According to Arctic Wolf Labs, this campaign leverages residential proxies to mask illegitimate logins as typical consumer activities. This method ensures that compromised sessions are maintained every eight hours, circumventing detection. The campaign is affecting a variety of sectors, including healthcare, education, manufacturing, and government, across the United States, Canada, and Europe.
The tactics bear similarities to those used in Payroll Pirate attacks, which Microsoft tracks under the label Storm-2755. These attacks often reroute salary payments to accounts controlled by the attackers, having been initially documented as early as 2025.
Complex Phishing Techniques Employed
The current wave of attacks involves hundreds of organizations being targeted through email-based phishing. Victims receive voicemail-themed emails leading them to AitM decoy sites, which replicate Microsoft’s authentication flow to capture login credentials and multi-factor authentication codes.
This attack utilizes a six-stage redirection chain that employs credible services such as Google and Amazon S3 to bypass reputation filters. The process begins with a Google Meet redirection link and culminates at Amazon’s S3 infrastructure, which then forwards the user to the phishing site.
Automation Enhances Attack Efficacy
JavaScript on the phishing pages collects detailed information about the visitor’s browser and system, which is then sent to a PHP endpoint. The threat actors use this data to maintain control of the sessions and gather emails from payroll and HR staff involved in financial transactions.
Further scrutiny reveals that these phishing activities originate from residential proxy nodes close to the victim’s location, utilizing geolocation data for optimal proxy selection. This technique helps evade security checks that block unfamiliar IP addresses.
Limited Detection Opportunities
Interestingly, despite gaining access, the attackers have refrained from modifying MFA methods or creating inbox rules, focusing solely on session maintenance and data collection. This restraint minimizes detection risks based on account changes or email anomalies.
In a few cases, attackers manually created inbox rules to move certain emails to the trash and mark them as read, suggesting selective intervention for account manipulation while relying on automation for most tasks.
Arctic Wolf concludes that the use of rotating proxies and centralized automation makes it challenging to trace the campaign back to its phishing origins, thereby complicating detection efforts.
