Domain
Arctic Wolf is tracking an active, widespread phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle (AiTM) techniques. The operation employs voicemail-themed phishing emails that redirect victims through multiple legitimate services to AiTM proxy infrastructure, which intercepts authentication sessions even when multi-factor authentication is enabled. Once compromised, threat actors use residential proxies to maintain access, conducting automated sign-ins at eight-hour intervals while collecting email from personnel involved in financial workflows. The campaign uses Microsoft Graph for reconnaissance targeting payroll, HR, and finance users, followed by coordinated mailbox collection. Activity affects organizations across healthcare, education, manufacturing, government, and professional services sectors in the United States, Canada, and Europe. The campaign shares characteristics with Microsoft-tracked Storm-2755 activity cluster.
No sightings recorded yet