Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AitM Phishing Targets Microsoft 365 for Payroll Data

AitM Phishing Targets Microsoft 365 for Payroll Data

Posted on August 7, 2026 By CWS

Cybersecurity experts are raising alarms over a significant phishing campaign deploying adversary-in-the-middle (AitM) tactics to breach Microsoft 365 accounts. The primary target is individuals involved in financial operations to access their emails and pertinent data.

Residential Proxies Mask Malicious Activity

According to Arctic Wolf Labs, this campaign leverages residential proxies to mask illegitimate logins as typical consumer activities. This method ensures that compromised sessions are maintained every eight hours, circumventing detection. The campaign is affecting a variety of sectors, including healthcare, education, manufacturing, and government, across the United States, Canada, and Europe.

The tactics bear similarities to those used in Payroll Pirate attacks, which Microsoft tracks under the label Storm-2755. These attacks often reroute salary payments to accounts controlled by the attackers, having been initially documented as early as 2025.

Complex Phishing Techniques Employed

The current wave of attacks involves hundreds of organizations being targeted through email-based phishing. Victims receive voicemail-themed emails leading them to AitM decoy sites, which replicate Microsoft’s authentication flow to capture login credentials and multi-factor authentication codes.

This attack utilizes a six-stage redirection chain that employs credible services such as Google and Amazon S3 to bypass reputation filters. The process begins with a Google Meet redirection link and culminates at Amazon’s S3 infrastructure, which then forwards the user to the phishing site.

Automation Enhances Attack Efficacy

JavaScript on the phishing pages collects detailed information about the visitor’s browser and system, which is then sent to a PHP endpoint. The threat actors use this data to maintain control of the sessions and gather emails from payroll and HR staff involved in financial transactions.

Further scrutiny reveals that these phishing activities originate from residential proxy nodes close to the victim’s location, utilizing geolocation data for optimal proxy selection. This technique helps evade security checks that block unfamiliar IP addresses.

Limited Detection Opportunities

Interestingly, despite gaining access, the attackers have refrained from modifying MFA methods or creating inbox rules, focusing solely on session maintenance and data collection. This restraint minimizes detection risks based on account changes or email anomalies.

In a few cases, attackers manually created inbox rules to move certain emails to the trash and mark them as read, suggesting selective intervention for account manipulation while relying on automation for most tasks.

Arctic Wolf concludes that the use of rotating proxies and centralized automation makes it challenging to trace the campaign back to its phishing origins, thereby complicating detection efforts.

The Hacker News Tags:AiTM phishing, Arctic Wolf, Cybersecurity, email security, finance emails, Microsoft 365, payroll data, phishing campaign, residential proxies, session hijacking, Storm-2755

Post navigation

Previous Post: CHAINDROP Malware Targets Over 400 npm Packages
Next Post: Vishing Group UNC6671 Restructures After Millions in Extortion

Related Posts

OFAC Sanctions North Korean IT Network Exploiting Remote Jobs OFAC Sanctions North Korean IT Network Exploiting Remote Jobs The Hacker News
Active Exploitation of PAN-OS VPN Vulnerability Alert Active Exploitation of PAN-OS VPN Vulnerability Alert The Hacker News
New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands The Hacker News
Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now The Hacker News
GreatXML Exploit Circumvents Windows BitLocker Security GreatXML Exploit Circumvents Windows BitLocker Security The Hacker News
Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Noopur Davis: From Developer to Comcast’s Global CISO
  • Weekly Security Recap: Cisco ISE Flaw & AI Vulnerabilities
  • Windows Updates Disrupt File History Backups in September 2026
  • Dragos Expands with NetRise and runZero Acquisitions
  • HEIF Image Vulnerability Exploited for Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Noopur Davis: From Developer to Comcast’s Global CISO
  • Weekly Security Recap: Cisco ISE Flaw & AI Vulnerabilities
  • Windows Updates Disrupt File History Backups in September 2026
  • Dragos Expands with NetRise and runZero Acquisitions
  • HEIF Image Vulnerability Exploited for Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark