Published on August 7, 2026

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails


Severity

High

Detail

A widespread phishing campaign is targeting Microsoft 365 users by leveraging Adversary-in-the-Middle (AitM) techniques to hijack authenticated sessions and bypass multi-factor authentication (MFA). The attackers focus on organizations across the healthcare, education, manufacturing, government, and professional services sectors, with the objective of identifying personnel involved in payroll, finance, and human resources functions and stealing sensitive email communications.

How?

The attack begins with voicemail-themed phishing emails containing links that ultimately redirect victims to a malicious AitM phishing page. The redirection chain abuses legitimate services, including Google Meet, Google Ads, and Amazon S3, to evade reputation-based email and web filtering.

The phishing page proxies the legitimate Microsoft 365 authentication process, enabling attackers to capture user credentials, session cookies, and MFA tokens in real time. Before presenting the login page, the site fingerprints the victim’s browser and system information including operating system, browser type, language, screen resolution, WebGL details, cookie settings, and geolocation data.

Once authentication is successfully intercepted, attackers use geographically matched residential proxy services to replay the stolen session from the victim’s country, helping bypass conditional access policies and anomaly-based detections. Automated infrastructure periodically refreshes compromised sessions approximately every eight hours to maintain persistent access.

After gaining access, the attackers enumerate Microsoft 365 users associated with payroll, finance, human resources, and administrative roles using the Microsoft Graph API. They then search and collect emails related to payroll processing, invoices, payments, banking information, employee benefits, and other financial communications. In some cases, attackers also create inbox rules to hide targeted emails by moving them to the Deleted Items folder and marking them as read.

Conclusion

This campaign demonstrates the growing sophistication of AitM phishing attacks, which can bypass traditional multi-factor authentication by stealing authenticated sessions instead of credentials alone. By combining trusted cloud services, residential proxy infrastructure, and automated session maintenance, attackers can quietly maintain long-term access to Microsoft 365 environments while collecting sensitive payroll and financial information. Organizations should strengthen identity security, continuously monitor authentication activities, and adopt phishing-resistant authentication methods to reduce the risk of account compromise.

Source

https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html