← Back to blog

Executives Targeted in Sophisticated Microsoft 365 Phishing Campaign

Cybercriminals are using fake IT support calls and token theft to breach executive Microsoft 365 accounts. The attacks leverage social engineering and residential proxies to bypass security measures.

TL;DR

  • Attackers impersonate IT help desk staff to target executives via phone-based phishing (vishing)
  • They use adversary-in-the-middle (AitM) techniques to steal authentication tokens
  • Residential proxies are used to mask login locations and avoid detection
  • Main targets include directors, VPs, and other high-level personnel
  • Organizations should implement advanced MFA and user awareness training

Threat actors are increasingly focusing on high-value targets within organizations by exploiting trusted communication channels. In a new wave of cyberattacks, executives are being targeted through convincing fake IT support calls designed to trick them into granting access to their Microsoft 365 accounts.

These sophisticated campaigns combine social engineering tactics with technical exploitation methods such as adversary-in-the-middle (AitM) attacks to capture session tokens. Once obtained, these credentials allow attackers to maintain persistent access while appearing as legitimate users.

Attack Vector Breakdown

  • Initial compromise occurs through vishing where attackers pose as internal IT support staff
  • Victims are convinced to visit spoofed login pages that capture credentials and session tokens
  • Adversary-in-the-middle (AitM) proxies intercept authentication traffic in real-time
  • Stolen tokens enable attackers to access email, files, and collaboration tools without triggering alerts

Defense Strategies

  • Implement robust multi-factor authentication beyond SMS-based codes
  • Train executives and key personnel on identifying social engineering attempts
  • Monitor for unusual login patterns, especially from residential IP addresses
  • Enforce conditional access policies based on device compliance and location
  • Deploy security solutions capable of detecting AitM infrastructure and anomalous sessions

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Executives Targeted in Sophisticated Microsoft 365 Phishing Campaign — Agent Breach Blog | Agent Breach