Listen to this Post
Introduction: A New Era of Invisible Business Email Compromise
Cybercriminals are increasingly moving away from noisy attacks that immediately reveal their presence. Instead, modern threat actors are adopting stealth-focused techniques designed to quietly enter organizations, remain hidden, and collect valuable intelligence before launching financial fraud.
A newly identified phishing campaign demonstrates this dangerous evolution. Security researchers have uncovered a widespread email-driven operation targeting Microsoft 365 accounts through adversary-in-the-middle (AitM) phishing attacks. Rather than simply stealing passwords, attackers are capturing authentication sessions, bypassing multi-factor authentication (MFA), and using residential proxy networks to disguise malicious activity as normal employee behavior.
The campaign has affected organizations across healthcare, education, manufacturing, government, and professional services sectors throughout the United States, Canada, and Europe. Researchers believe the operation shares similarities with financially motivated groups such as Microsoft’s tracked threat clusters Storm-2755 and Storm-2657, which have previously focused on payroll theft and business email compromise (BEC).
This campaign highlights a growing cybersecurity challenge: attackers are no longer only trying to break into accounts. They are attempting to become invisible users inside corporate environments.
Original Incident Summary: Attackers Target Microsoft 365 Through Advanced Phishing
Hundreds of Organizations Targeted Through Email Campaigns
According to Arctic Wolf Labs, hundreds of organizations were targeted through malicious emails during the latest campaign. Successful compromises were observed across different industries, showing that the attackers are not limiting themselves to a specific sector.
The primary objective appears to be identifying employees connected to financial processes, payroll operations, human resources departments, and payment workflows. By gaining access to these accounts, attackers can monitor sensitive conversations and prepare future financial fraud attempts.
Unlike traditional ransomware attacks that immediately disrupt operations, this campaign focuses on intelligence gathering and long-term access.
Deep Analysis: How the Microsoft 365 Phishing Operation Works
Stage One: Voicemail-Themed Phishing Emails Begin the Attack
The attack starts with carefully crafted phishing emails designed to appear legitimate. Researchers observed voicemail-themed messages that encourage recipients to click a link to review a supposed voice message.
These emails exploit human curiosity and urgency. Employees often respond quickly to messages involving missed calls, voice notifications, or internal communication alerts.
The attackers use this psychological pressure to move victims toward fraudulent Microsoft login pages.
Stage Two: Adversary-in-the-Middle Pages Steal Authentication Sessions
Instead of creating a simple fake login page, attackers deploy AitM phishing infrastructure.
These malicious websites sit between the victim and Microsoft’s real authentication system. When users enter credentials and complete MFA verification, the attackers capture authentication tokens and session information.
This approach allows criminals to bypass traditional MFA protections because they are not only stealing passwords. They are stealing already-authenticated sessions.
Stage Three: Trusted Services Used to Hide Malicious Infrastructure
One of the most concerning elements of this campaign is the abuse of legitimate internet services.
The attack chain uses trusted platforms including:
Google redirect infrastructure
Google Meet links
Google Ads tracking systems
Amazon Web Services S3 hosting
The six-stage redirection process helps attackers avoid reputation-based security filters.
The victim does not immediately reach a suspicious domain. Instead, they are redirected through trusted services before arriving at the final phishing infrastructure.
This technique demonstrates how cybercriminals increasingly exploit legitimate platforms as part of malicious operations.
Browser Fingerprinting: Attackers Collect Victim Intelligence
JavaScript Used to Profile Target Devices
Before delivering the phishing page, attackers use JavaScript-based fingerprinting techniques to collect information about victims.
The scripts gather:
Browser type
Operating system details
Screen dimensions
Language settings
Time zone information
Cookie availability
WebDriver detection
WebGL information
Browser API availability
This information helps attackers determine whether the visitor is a real employee, a security researcher, or an automated scanning system.
The collected data is sent to attacker-controlled PHP endpoints before victims are redirected to the fake Microsoft OAuth authentication page.
Residential Proxies Allow Attackers to Blend Into Normal Traffic
Criminals Mimic Local Employee Login Behavior
One of the most advanced parts of this operation is the use of residential proxy networks.
Residential proxies allow attackers to make malicious login attempts appear as if they are coming from ordinary home internet connections.
Researchers found that attackers selected proxy exit nodes located inside the same countries as their victims.
This strategy reduces suspicion because security systems often flag foreign login attempts. A login from the same country appears much more believable.
Automated Sessions Refresh Every Eight Hours
After compromising accounts, attackers maintain access through automated systems.
Researchers observed malicious sign-ins repeating approximately every eight hours from rotating residential IP addresses.
Although the source locations changed, the same session identifiers remained active, suggesting that centralized automation was managing stolen authentication sessions.
This creates a major detection challenge because the activity resembles normal account usage.
Impossible Browser Combinations Reveal Hidden Automation
Attackers Attempt to Imitate Legitimate Users
Security researchers discovered suspicious combinations between reported applications, browsers, and operating systems.
Examples included:
Mobile Safari appearing alongside Windows environments
Chrome versions inconsistent with normal user behavior
Firefox user agents while Microsoft Outlook was reported as the client
These inconsistencies indicate that automated tools are controlling compromised sessions.
Attackers are attempting to imitate employee activity while avoiding obvious indicators of compromise.
Microsoft Graph API Abuse Expands Internal Reconnaissance
Attackers Search for Valuable Employees and Financial Data
After gaining access, threat actors use Microsoft Graph API to explore organizational environments.
They specifically search for accounts connected to:
Payroll
Human resources
Finance
Administration
Payment processing
They also search mailbox content related to:
Salary payments
Banking information
Vendor invoices
Benefits
Internal financial documents
The objective is not immediate destruction. The goal is intelligence collection that enables future financial attacks.
Why This Campaign Is More Dangerous Than Traditional BEC
Attackers Avoid Actions That Trigger Security Alerts
Traditional business email compromise attacks often create obvious warning signs.
Attackers may:
Change MFA settings
Register new devices
Reset passwords
Create forwarding rules
Send phishing emails from compromised accounts
However, this campaign avoids many of these behaviors.
Researchers found that attackers mainly focused on maintaining access, collecting emails, and observing financial workflows.
This quiet approach reduces detection opportunities.
Selective Human Intervention Shows a Hybrid Attack Model
Automation Combined With Manual Control
Although much of the operation appears automated, some cases showed manual attacker involvement.
Researchers observed attackers creating inbox rules that:
Moved messages from Inbox to Deleted Items
Marked emails as read
This suggests a hybrid strategy.
Automated systems handle large-scale account monitoring, while human operators intervene when valuable accounts or financial opportunities are discovered.
What Undercode Say:
A New Generation of Business Email Compromise
The Microsoft 365 phishing campaign represents a significant evolution in cybercrime operations. Attackers are no longer depending only on stolen credentials. They are stealing trust, identity, and authenticated sessions.
MFA Is No Longer a Complete Defense
Multi-factor authentication remains important, but AitM attacks demonstrate that session theft can bypass many traditional MFA protections.
Organizations must move toward stronger identity protection systems that monitor authentication behavior rather than only verifying login credentials.
Residential Proxy Abuse Creates Detection Problems
The use of residential proxies represents a major challenge for defenders.
A malicious login from a residential IP inside the victim’s country can appear completely normal.
Security teams must analyze behavior patterns, device fingerprints, session activity, and impossible combinations rather than relying only on geographic indicators.
Attackers Are Becoming Patient
This campaign shows that cybercriminals are increasingly willing to wait.
Instead of immediately stealing money, attackers spend days or weeks mapping organizations, identifying valuable employees, and collecting information.
The intelligence gathered today can become the foundation for future fraud.
Financial Departments Remain Prime Targets
Payroll and finance employees continue to be among the most valuable targets because access to their communications can directly lead to financial theft.
Organizations should provide additional monitoring and security controls for employees involved in payment processes.
Identity Has Become the New Security Battlefield
Modern attacks increasingly focus on identities rather than infrastructure.
A compromised employee account can provide attackers with more value than exploiting a technical vulnerability.
Security strategies must therefore prioritize identity protection, continuous authentication monitoring, and user behavior analytics.
Deep Analysis Commands
Command 1: Monitor Authentication Behavior
Organizations should analyze login patterns, session persistence, unusual user agents, and abnormal authentication sequences.
Command 2: Detect Token Theft Indicators
Security teams should monitor suspicious OAuth activity, unexpected API access, and unusual Microsoft Graph API requests.
Command 3: Protect Financial Communication Channels
Payroll, HR, and finance mailboxes require additional monitoring because attackers specifically target these workflows.
Command 4: Reduce Phishing Success Rates
Companies should strengthen email filtering, phishing awareness programs, and simulated attack testing.
Command 5: Deploy Identity-Based Detection
Security tools should evaluate whether login behavior matches normal employee activity instead of relying only on passwords and MFA.
✅ Confirmed: Arctic Wolf Labs reported an active phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle techniques and residential proxies.
✅ Confirmed: The campaign affected multiple industries, including healthcare, education, manufacturing, government, and professional services organizations.
❌ Not Confirmed: There is currently no public evidence that this campaign caused widespread direct financial losses across all targeted organizations.
Prediction: The Future of Identity-Based Cyberattacks
(+1) Stronger Identity Security Will Reduce Attack Success
Organizations that adopt continuous authentication monitoring, phishing-resistant MFA, and advanced identity analytics will significantly reduce the effectiveness of these attacks.
(-1) Attackers Will Continue Exploiting Session Theft
Cybercriminal groups are expected to invest more heavily in token theft, proxy networks, and automated account monitoring because these techniques bypass many traditional security defenses.
(-1) Financial Teams Will Remain High-Value Targets
Payroll, accounting, and human resources departments will likely continue facing targeted attacks because access to their communications can provide direct financial opportunities.
(+1) AI-Based Detection Could Improve Defense
Artificial intelligence-driven security systems may become increasingly effective at identifying abnormal login behavior, impossible device combinations, and suspicious session activity.
(-1) Legitimate Cloud Services Will Continue Being Abused
Attackers will likely continue hiding malicious infrastructure behind trusted platforms such as cloud storage providers, advertising systems, and collaboration services, making detection more difficult.
▶️ Related Video (76% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




