ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Microsoft 365 AitM phishing takes over accounts to harvest payroll emails

Source headline: Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Threat level High
Signal strength 70/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

A current phishing campaign uses adversary-in-the-middle techniques to hijack Microsoft 365 accounts. Victims are targeted to identify personnel tied to payroll and finance workflows. The attackers then collect related email content to support follow-on activity. Researchers report the use of residential proxies to make logins appear like normal consumer traffic. Organizations using Microsoft 365 should review sign-in anomalies, enforce stronger authentication, and monitor for suspicious OAuth and session behavior.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#phishing #residential-proxies #aitm #microsoft365 #email-harvesting
Original reporting The Hacker News Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Open original source