Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
An active AitM phishing campaign targets M365 accounts of payroll and finance staff to intercept financial communications — a refined BEC precursor requiring token-binding defences.
Summary written by editorial AI · Source link below
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.
"The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,
Editorial Analysis
By specifically targeting financial workflow personnel, attackers are refining BEC tactics with session-token theft, making phishing-resistant MFA and token-binding essential, not optional.
Enable Conditional Access token-binding and continuous access evaluation for M365 sessions, especially for finance teams.
Phishing campaigns are now stealing live M365 sessions from finance staff, requiring stronger authentication controls to prevent funds diversion.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d