Cybersecurity experts have flagged a significant phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle techniques. This campaign specifically aims to infiltrate organizations by identifying key personnel involved in financial operations and collecting related emails. The attackers employ residential proxies to camouflage their malicious activities as typical consumer traffic, ensuring compromised sessions are maintained at eight-hour intervals. The campaign impacts a wide range of sectors, including healthcare, education, manufacturing, government, and professional services across the United States, Canada, and Europe.

The campaign shares similarities with attacks known as Payroll Pirates, which Microsoft tracks under the name Storm-2755. These attacks involve hijacking employee accounts to redirect salary payments to accounts controlled by the attackers. Arctic Wolf Labs has observed hundreds of organizations targeted by this recent phishing campaign, which uses voicemail-themed phishing emails to lure victims into adversary-in-the-middle decoy pages. These pages serve as proxies for legitimate Microsoft authentication processes, capturing credentials and multi-factor authentication codes.

The phishing attacks utilize a sophisticated six-stage redirection chain featuring trusted services like Google and Amazon to bypass security filters. Once victims are redirected to the phishing infrastructure, the attackers gather detailed information, such as browser and operating system specifics, through JavaScript. This information is sent to a PHP endpoint before redirecting the victim to the Microsoft OAuth authorization endpoint. The attackers further leverage geolocation data, using residential proxies matching the victim's country to evade security controls.

While most observed intrusions focus on session maintenance and mailbox collection, a few instances involved direct manipulation of account settings. The attackers' strategy of restrained post-compromise activity and reliance on centralized automation makes it challenging to detect these intrusions early. The campaign's sophistication, combined with its focus on financial data, underscores the urgent need for organizations to enhance their security measures.