← Back to blog

Microsoft 365 Phishing Campaign Uses AitM Tactics to Target Finance Teams

Attackers are exploiting Microsoft 365 accounts using Adversary-in-the-Middle techniques to access sensitive payroll and financial data. The campaign leverages residential proxies to mask malicious activity as legitimate user traffic.

TL;DR

  • Active phishing campaign targets Microsoft 365 users with AitM attacks
  • Goal is to infiltrate finance departments and collect payroll-related emails
  • Uses residential proxies to evade detection by mimicking normal traffic
  • Focuses on identifying key personnel in financial workflows
  • Organizations should enhance MFA monitoring and user behavior analytics

Security researchers have uncovered a widespread phishing operation targeting Microsoft 365 users through advanced Adversary-in-the-Middle (AitM) techniques. Unlike traditional phishing methods, this campaign focuses on gaining persistent access to business email accounts to monitor and collect communications related to financial operations.

The attackers employ residential proxies to blend malicious login attempts with regular internet traffic, making detection more challenging for standard security tools. Once inside compromised accounts, they specifically search for users involved in payroll processing and other financial workflows, indicating a strategic interest in monetary fraud rather than broad data theft.

Attack Methodology

  • Campaign uses Adversary-in-the-Middle (AitM) techniques to intercept authentication sessions
  • Residential proxies disguise attack traffic as legitimate consumer internet usage
  • Focuses on compromising Microsoft 365 accounts with access to financial systems
  • Targets specific user roles involved in payroll, accounting, and payment processing

Security Recommendations

  • Implement enhanced monitoring for unusual authentication patterns and geographic anomalies
  • Deploy conditional access policies that restrict access from residential IP ranges
  • Strengthen multi-factor authentication with passwordless methods where possible
  • Conduct regular security awareness training focused on sophisticated phishing techniques
  • Review and audit user permissions regularly, especially for finance-related accounts

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Microsoft 365 Phishing Campaign Uses AitM Tactics to Target Finance Teams — Agent Breach Blog | Agent Breach