ShellCodeX Intelligence Brief
HIGH
Cybersecurity
Microsoft 365 AitM phishing takes over accounts to harvest payroll emails
Source headline: Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Threat level
High
Signal strength
70/100
Source confidence
1 source
Published
1 hour ago
Intelligence Summary
A current phishing campaign uses adversary-in-the-middle techniques to hijack Microsoft 365 accounts. Victims are targeted to identify personnel tied to payroll and finance workflows. The attackers then collect related email content to support follow-on activity. Researchers report the use of residential proxies to make logins appear like normal consumer traffic. Organizations using Microsoft 365 should review sign-in anomalies, enforce stronger authentication, and monitor for suspicious OAuth and session behavior.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
The Hacker News
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Open original source