Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AitM Phishing Targets Microsoft 365 for Payroll Data

AitM Phishing Targets Microsoft 365 for Payroll Data

Posted on August 7, 2026 By CWS

Cybersecurity experts are raising alarms over a significant phishing campaign deploying adversary-in-the-middle (AitM) tactics to breach Microsoft 365 accounts. The primary target is individuals involved in financial operations to access their emails and pertinent data.

Residential Proxies Mask Malicious Activity

According to Arctic Wolf Labs, this campaign leverages residential proxies to mask illegitimate logins as typical consumer activities. This method ensures that compromised sessions are maintained every eight hours, circumventing detection. The campaign is affecting a variety of sectors, including healthcare, education, manufacturing, and government, across the United States, Canada, and Europe.

The tactics bear similarities to those used in Payroll Pirate attacks, which Microsoft tracks under the label Storm-2755. These attacks often reroute salary payments to accounts controlled by the attackers, having been initially documented as early as 2025.

Complex Phishing Techniques Employed

The current wave of attacks involves hundreds of organizations being targeted through email-based phishing. Victims receive voicemail-themed emails leading them to AitM decoy sites, which replicate Microsoft’s authentication flow to capture login credentials and multi-factor authentication codes.

This attack utilizes a six-stage redirection chain that employs credible services such as Google and Amazon S3 to bypass reputation filters. The process begins with a Google Meet redirection link and culminates at Amazon’s S3 infrastructure, which then forwards the user to the phishing site.

Automation Enhances Attack Efficacy

JavaScript on the phishing pages collects detailed information about the visitor’s browser and system, which is then sent to a PHP endpoint. The threat actors use this data to maintain control of the sessions and gather emails from payroll and HR staff involved in financial transactions.

Further scrutiny reveals that these phishing activities originate from residential proxy nodes close to the victim’s location, utilizing geolocation data for optimal proxy selection. This technique helps evade security checks that block unfamiliar IP addresses.

Limited Detection Opportunities

Interestingly, despite gaining access, the attackers have refrained from modifying MFA methods or creating inbox rules, focusing solely on session maintenance and data collection. This restraint minimizes detection risks based on account changes or email anomalies.

In a few cases, attackers manually created inbox rules to move certain emails to the trash and mark them as read, suggesting selective intervention for account manipulation while relying on automation for most tasks.

Arctic Wolf concludes that the use of rotating proxies and centralized automation makes it challenging to trace the campaign back to its phishing origins, thereby complicating detection efforts.

The Hacker News Tags:AiTM phishing, Arctic Wolf, Cybersecurity, email security, finance emails, Microsoft 365, payroll data, phishing campaign, residential proxies, session hijacking, Storm-2755

Post navigation

Previous Post: CHAINDROP Malware Targets Over 400 npm Packages

Related Posts

AI-Hallucinated Domains Exploited in Phishing Scams AI-Hallucinated Domains Exploited in Phishing Scams The Hacker News
SmartLoader Malware Exploits Oura Server for Data Theft SmartLoader Malware Exploits Oura Server for Data Theft The Hacker News
Validate Security Measures Against Real Threats Validate Security Measures Against Real Threats The Hacker News
RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer The Hacker News
Critical 18-Year NGINX Vulnerability Enables Remote Code Execution Critical 18-Year NGINX Vulnerability Enables Remote Code Execution The Hacker News
Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AitM Phishing Targets Microsoft 365 for Payroll Data
  • CHAINDROP Malware Targets Over 400 npm Packages
  • Bendix Brake Controller Recall Exposes Hidden Security Risks
  • NatJack Exploits NAT Vulnerabilities to Hijack TCP and DNS
  • Critical Vulnerabilities in Enterprise Java Platforms Uncovered

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AitM Phishing Targets Microsoft 365 for Payroll Data
  • CHAINDROP Malware Targets Over 400 npm Packages
  • Bendix Brake Controller Recall Exposes Hidden Security Risks
  • NatJack Exploits NAT Vulnerabilities to Hijack TCP and DNS
  • Critical Vulnerabilities in Enterprise Java Platforms Uncovered

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark