Cybersecurity researchers have identified an active "extensive email phishing campaign" that uses adversary-in-the-middle (AitM) to gain control of Microsoft 365. The goal is to identify key individuals involved in financial workflows and harvest relevant emails.
See also: Kratos Phishing Kit: Infrastructure that was stealing Microsoft 365 sessions taken down

According to Arctic Wolf Labs, “The campaign uses home-grown intermediaries to disguise malicious connections as normal consumer traffic.” The automated activity maintains compromised sessions for approximately eight hours.
This activity is believed to be affecting organizations across a variety of sectors, including healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe. It shares tactical similarities with the Payroll Pirate attacks that Microsoft is tracking under the name Storm-2755.
Payroll Pirates refers to a broader financially motivated threat that hijacks employee accounts to redirect payroll payments to accounts controlled by attackers. Some aspects of these campaigns have been documented since early 2025, with Microsoft tracking a related threat as Storm-2657.
Arctic Wolf reported that it observed hundreds of organizations being targeted via email as part of the latest phishing campaign last month, leading to successful breaches across a wide range of victim environments.
The attack chains include phishing emails themed around voicemails that direct victims to AitM decoy pages, which act as an intermediary for the legitimate Microsoft account authentication flow, secretly capturing credentials and multi-factor authentication (MFA) codes.
This is achieved through a six-step redirect chain that uses legitimate services like Google, Google Meet, Google Ads , and Amazon S3 to bypass reputation-based filters. The chain starts with a Google Meet redirect link and continues through Google's external link infrastructure before reaching a Campaign Manager dynamic click tracker.
See also: Forg365: New phishing platform targets Microsoft 365 accounts

The destination embedded in the tracking link points to an HTML object hosted in an Amazon AWS S3 bucket, which then redirects the victim to the campaign's AitM phishing infrastructure.
Phishing pages also use JavaScript to record visitor characteristics, collecting information about the browser, operating system, screen and window dimensions, browser language, time zone offset, cookie capabilities, WebDriver status, WebGL vendor, and browser API availability.
This information is sent to a PHP endpoint via an HTTP POST request, after which the script redirects the browser to the Microsoft OAuth authorized point.
Additionally, a geolocation API is queried for the requester's country code and the result is stored in a cookie with a seven-day expiration. Once initial access is gained, the attacker exploits the compromised sessions to harvest emails from payroll and HR personnel involved in financial matters.
Controlled testing indicates that malicious connection activity originates within minutes from a home proxy exit node in the victim's country, suggesting that attackers may be using geolocation data to select geographically matched proxy infrastructure for subsequent connections, thereby bypassing security checks that prevent access from unusual IP addresses.
See also: FBI: Kali365 phishing service targets Microsoft 365 accounts
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Some connection events report “unlikely browser and operating system combinations,” such as mobile versions of Apple Safari or Google Chrome on Windows 10. Typically, 11 to 24 hours after the initial anomalous activity, malicious connections begin to recur at eight-hour intervals from rotating home proxy addresses.
