A widespread phishing campaign actively targets Microsoft 365 accounts using adversary-in-the-middle (AitM) techniques to hijack credentials and harvest payroll and finance-related emails, cybersecurity researchers warn.

The attack chain relies on email-based phishing to trick users into surrendering login credentials. Once attackers gain account access, they deploy residential proxies to mask malicious sign-ins as legitimate consumer traffic. This obfuscation layer defeats standard anomaly detection systems that flag logins from suspicious geographies or IP ranges.

The campaign's objective centers on identifying finance and payroll personnel within target organisations. After compromising accounts, attackers exfiltrate emails containing financial data, banking details, vendor information, and payment instructions. This intelligence enables downstream fraud attacks, wire transfer schemes, or business email compromise (BEC) operations.

The residential proxy component proves particularly dangerous. Unlike datacenter proxies, residential IPs originate from actual consumer devices, making them indistinguishable from normal user behaviour to security tools. Microsoft 365 environments relying solely on IP-based detection will struggle to flag these intrusions until lateral movement occurs or data exfiltration patterns emerge.

Organisations should implement multi-factor authentication (MFA) across all Microsoft 365 accounts, particularly for finance and HR staff who handle sensitive workflows. Email filtering rules should flag suspicious forwarding rules created post-compromise, a common attacker tactic for maintaining persistence and monitoring communications.

Conditional Access policies should enforce restrictions based on sign-in risk scores rather than IP reputation alone. Session anomaly detection tools that monitor for unusual email access patterns, rapid mailbox rule creation, or bulk forwarding will catch compromised accounts faster than network-level controls.

Users in finance roles require heightened phishing awareness training. Attackers specifically target these personnel, so organisations should consider separate security protocols for accounts with payment approval