Microsoft 365 Accounts Under Silent Siege: Widespread Phishing Campaign Uses Residential Proxies to Hijack Financial Operations + Video

Listen to this Post

Featured ImageIntroduction: A New Era of Invisible Business Email Compromise

Cybercriminals are increasingly moving away from noisy attacks that immediately reveal their presence. Instead, modern threat actors are adopting stealth-focused techniques designed to quietly enter organizations, remain hidden, and collect valuable intelligence before launching financial fraud.

A newly identified phishing campaign demonstrates this dangerous evolution. Security researchers have uncovered a widespread email-driven operation targeting Microsoft 365 accounts through adversary-in-the-middle (AitM) phishing attacks. Rather than simply stealing passwords, attackers are capturing authentication sessions, bypassing multi-factor authentication (MFA), and using residential proxy networks to disguise malicious activity as normal employee behavior.

The campaign has affected organizations across healthcare, education, manufacturing, government, and professional services sectors throughout the United States, Canada, and Europe. Researchers believe the operation shares similarities with financially motivated groups such as Microsoft’s tracked threat clusters Storm-2755 and Storm-2657, which have previously focused on payroll theft and business email compromise (BEC).

This campaign highlights a growing cybersecurity challenge: attackers are no longer only trying to break into accounts. They are attempting to become invisible users inside corporate environments.

Original Incident Summary: Attackers Target Microsoft 365 Through Advanced Phishing

Hundreds of Organizations Targeted Through Email Campaigns

According to Arctic Wolf Labs, hundreds of organizations were targeted through malicious emails during the latest campaign. Successful compromises were observed across different industries, showing that the attackers are not limiting themselves to a specific sector.

The primary objective appears to be identifying employees connected to financial processes, payroll operations, human resources departments, and payment workflows. By gaining access to these accounts, attackers can monitor sensitive conversations and prepare future financial fraud attempts.

Unlike traditional ransomware attacks that immediately disrupt operations, this campaign focuses on intelligence gathering and long-term access.

Deep Analysis: How the Microsoft 365 Phishing Operation Works
Stage One: Voicemail-Themed Phishing Emails Begin the Attack

The attack starts with carefully crafted phishing emails designed to appear legitimate. Researchers observed voicemail-themed messages that encourage recipients to click a link to review a supposed voice message.

These emails exploit human curiosity and urgency. Employees often respond quickly to messages involving missed calls, voice notifications, or internal communication alerts.

The attackers use this psychological pressure to move victims toward fraudulent Microsoft login pages.

Stage Two: Adversary-in-the-Middle Pages Steal Authentication Sessions

Instead of creating a simple fake login page, attackers deploy AitM phishing infrastructure.

These malicious websites sit between the victim and Microsoft’s real authentication system. When users enter credentials and complete MFA verification, the attackers capture authentication tokens and session information.

This approach allows criminals to bypass traditional MFA protections because they are not only stealing passwords. They are stealing already-authenticated sessions.

Stage Three: Trusted Services Used to Hide Malicious Infrastructure

One of the most concerning elements of this campaign is the abuse of legitimate internet services.

The attack chain uses trusted platforms including:

Google redirect infrastructure

Google Meet links

Google Ads tracking systems

Amazon Web Services S3 hosting

The six-stage redirection process helps attackers avoid reputation-based security filters.

The victim does not immediately reach a suspicious domain. Instead, they are redirected through trusted services before arriving at the final phishing infrastructure.

This technique demonstrates how cybercriminals increasingly exploit legitimate platforms as part of malicious operations.

Browser Fingerprinting: Attackers Collect Victim Intelligence

JavaScript Used to Profile Target Devices

Before delivering the phishing page, attackers use JavaScript-based fingerprinting techniques to collect information about victims.

The scripts gather:

Browser type

Operating system details

Screen dimensions

Language settings

Time zone information

Cookie availability

WebDriver detection

WebGL information

Browser API availability

This information helps attackers determine whether the visitor is a real employee, a security researcher, or an automated scanning system.

The collected data is sent to attacker-controlled PHP endpoints before victims are redirected to the fake Microsoft OAuth authentication page.

Residential Proxies Allow Attackers to Blend Into Normal Traffic

Criminals Mimic Local Employee Login Behavior

One of the most advanced parts of this operation is the use of residential proxy networks.

Residential proxies allow attackers to make malicious login attempts appear as if they are coming from ordinary home internet connections.

Researchers found that attackers selected proxy exit nodes located inside the same countries as their victims.

This strategy reduces suspicion because security systems often flag foreign login attempts. A login from the same country appears much more believable.

Automated Sessions Refresh Every Eight Hours

After compromising accounts, attackers maintain access through automated systems.

Researchers observed malicious sign-ins repeating approximately every eight hours from rotating residential IP addresses.

Although the source locations changed, the same session identifiers remained active, suggesting that centralized automation was managing stolen authentication sessions.

This creates a major detection challenge because the activity resembles normal account usage.

Impossible Browser Combinations Reveal Hidden Automation

Attackers Attempt to Imitate Legitimate Users

Security researchers discovered suspicious combinations between reported applications, browsers, and operating systems.

Examples included:

Mobile Safari appearing alongside Windows environments

Chrome versions inconsistent with normal user behavior

Firefox user agents while Microsoft Outlook was reported as the client

These inconsistencies indicate that automated tools are controlling compromised sessions.

Attackers are attempting to imitate employee activity while avoiding obvious indicators of compromise.

Microsoft Graph API Abuse Expands Internal Reconnaissance

Attackers Search for Valuable Employees and Financial Data

After gaining access, threat actors use Microsoft Graph API to explore organizational environments.

They specifically search for accounts connected to:

Payroll

Human resources

Finance

Administration

Payment processing

They also search mailbox content related to:

Salary payments

Banking information

Vendor invoices

Benefits

Internal financial documents

The objective is not immediate destruction. The goal is intelligence collection that enables future financial attacks.

Why This Campaign Is More Dangerous Than Traditional BEC

Attackers Avoid Actions That Trigger Security Alerts

Traditional business email compromise attacks often create obvious warning signs.

Attackers may:

Change MFA settings

Register new devices

Reset passwords

Create forwarding rules

Send phishing emails from compromised accounts

However, this campaign avoids many of these behaviors.

Researchers found that attackers mainly focused on maintaining access, collecting emails, and observing financial workflows.

This quiet approach reduces detection opportunities.

Selective Human Intervention Shows a Hybrid Attack Model

Automation Combined With Manual Control

Although much of the operation appears automated, some cases showed manual attacker involvement.

Researchers observed attackers creating inbox rules that:

Moved messages from Inbox to Deleted Items

Marked emails as read

This suggests a hybrid strategy.

Automated systems handle large-scale account monitoring, while human operators intervene when valuable accounts or financial opportunities are discovered.

What Undercode Say:

A New Generation of Business Email Compromise

The Microsoft 365 phishing campaign represents a significant evolution in cybercrime operations. Attackers are no longer depending only on stolen credentials. They are stealing trust, identity, and authenticated sessions.

MFA Is No Longer a Complete Defense

Multi-factor authentication remains important, but AitM attacks demonstrate that session theft can bypass many traditional MFA protections.

Organizations must move toward stronger identity protection systems that monitor authentication behavior rather than only verifying login credentials.

Residential Proxy Abuse Creates Detection Problems

The use of residential proxies represents a major challenge for defenders.

A malicious login from a residential IP inside the victim’s country can appear completely normal.

Security teams must analyze behavior patterns, device fingerprints, session activity, and impossible combinations rather than relying only on geographic indicators.

Attackers Are Becoming Patient

This campaign shows that cybercriminals are increasingly willing to wait.

Instead of immediately stealing money, attackers spend days or weeks mapping organizations, identifying valuable employees, and collecting information.

The intelligence gathered today can become the foundation for future fraud.

Financial Departments Remain Prime Targets

Payroll and finance employees continue to be among the most valuable targets because access to their communications can directly lead to financial theft.

Organizations should provide additional monitoring and security controls for employees involved in payment processes.

Identity Has Become the New Security Battlefield

Modern attacks increasingly focus on identities rather than infrastructure.

A compromised employee account can provide attackers with more value than exploiting a technical vulnerability.

Security strategies must therefore prioritize identity protection, continuous authentication monitoring, and user behavior analytics.

Deep Analysis Commands

Command 1: Monitor Authentication Behavior

Organizations should analyze login patterns, session persistence, unusual user agents, and abnormal authentication sequences.

Command 2: Detect Token Theft Indicators

Security teams should monitor suspicious OAuth activity, unexpected API access, and unusual Microsoft Graph API requests.

Command 3: Protect Financial Communication Channels

Payroll, HR, and finance mailboxes require additional monitoring because attackers specifically target these workflows.

Command 4: Reduce Phishing Success Rates

Companies should strengthen email filtering, phishing awareness programs, and simulated attack testing.

Command 5: Deploy Identity-Based Detection

Security tools should evaluate whether login behavior matches normal employee activity instead of relying only on passwords and MFA.

✅ Confirmed: Arctic Wolf Labs reported an active phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle techniques and residential proxies.

✅ Confirmed: The campaign affected multiple industries, including healthcare, education, manufacturing, government, and professional services organizations.

❌ Not Confirmed: There is currently no public evidence that this campaign caused widespread direct financial losses across all targeted organizations.

Prediction: The Future of Identity-Based Cyberattacks

(+1) Stronger Identity Security Will Reduce Attack Success

Organizations that adopt continuous authentication monitoring, phishing-resistant MFA, and advanced identity analytics will significantly reduce the effectiveness of these attacks.

(-1) Attackers Will Continue Exploiting Session Theft

Cybercriminal groups are expected to invest more heavily in token theft, proxy networks, and automated account monitoring because these techniques bypass many traditional security defenses.

(-1) Financial Teams Will Remain High-Value Targets

Payroll, accounting, and human resources departments will likely continue facing targeted attacks because access to their communications can provide direct financial opportunities.

(+1) AI-Based Detection Could Improve Defense

Artificial intelligence-driven security systems may become increasingly effective at identifying abnormal login behavior, impossible device combinations, and suspicious session activity.

(-1) Legitimate Cloud Services Will Continue Being Abused

Attackers will likely continue hiding malicious infrastructure behind trusted platforms such as cloud storage providers, advertising systems, and collaboration services, making detection more difficult.

▶️ Related Video (76% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube