Phishing Campaign Compromises Microsoft 365 Accounts Using AiTM Techniques
A sophisticated phishing campaign has been identified by Arctic Wolf, targeting organizations across various sectors and regions. The campaign uses adversary-in-the-middle (AiTM) techniques to compromise Microsoft 365 accounts and collect related email associated with personnel involved in financial workflows.
The phishing emails impersonate an automated call notification service and direct recipients to a fraudulent voicemail portal. Once access is established, the actor quietly maintains compromised sessions and collects email data.
The campaign shares significant technical and behavioral overlap with the 'Payroll Pirates' activity cluster Microsoft tracks as Storm-2755. Arctic Wolf's investigation identified affected individuals across multiple geographic regions, suggesting a wider scope of targeting than originally reported.