Attackers are posing as IT support staff to steal credentials from corporate executives, gaining access to Microsoft 365 accounts and other cloud services. Security researchers have documented a coordinated threat campaign that combines phone-based social engineering with technical attacks to compromise high-value targets across multiple organizations.

The attack chain begins with vishing calls. Attackers impersonate IT help desk personnel and contact company executives, typically directors and vice presidents. During these calls, they convince targets to visit fake login portals or install malicious software. The goal remains straightforward: capture authentication credentials before the victim realizes the deception.

Once attackers obtain login credentials, they deploy adversary-in-the-middle (AitM) techniques to intercept session tokens. These tokens act as digital keys that grant access to cloud accounts without requiring repeated authentication. By stealing tokens, attackers bypass multi-factor authentication protections that would normally block unauthorized access using compromised passwords alone.

The attackers then sign into stolen accounts using residential proxies. These proxies route traffic through legitimate residential IP addresses rather than obvious data center infrastructure. This masking technique makes malicious logins appear to originate from normal business locations, helping attackers avoid detection by security monitoring systems that flag suspicious geographic patterns or unusual access sources.

The campaign specifically targets Microsoft 365 environments alongside other SaaS platforms. Once inside executive accounts, threat actors gain visibility into sensitive emails, files, and organizational data. They exfiltrate this information and then demand ransom payments, threatening to publish stolen data or leverage it for further extortion.

This attack vector presents particular risk to organizations because it exploits human trust rather than software vulnerabilities. Executives frequently receive support requests, making them easier targets for social engineering. Vishing attacks also bypass email-based security filters that screen for phishing links or malicious attachments. A voice call feels more authentic than a suspicious email, increasing success rates.

The focus on executive-level accounts multiplies the damage. Vice presidents and directors typically maintain access to confidential strategic plans, financial information, merger details, and customer databases. Compromising these accounts grants attackers comprehensive organizational intelligence they can monetize through extortion or sale to competitors.

Organizations should implement several defenses against this threat cluster. Security awareness training must specifically address vishing tactics and teach employees to verify support requests through established phone numbers rather than trusting incoming calls. Microsoft 365 administrators should enforce conditional access policies that restrict logins from unusual locations or devices. Token protection tools can detect and block AitM attacks. Companies should also monitor for impossible travel scenarios where the same account logs in from geographically distant locations within short timeframes.

The use of residential proxies represents a tactical evolution in this threat cluster. Traditional IP reputation systems struggle to flag residential addresses as malicious since they're used by legitimate users. This forces defenders to rely more heavily on behavioral analysis and device posture validation rather than simple geographic restrictions.

Incident response teams should treat any confirmed credential theft as a breach requiring immediate token revocation, password resets, and forensic investigation. Attackers who successfully steal executive credentials often maintain persistence mechanisms for weeks before launching data exfiltration, giving defenders a narrow window to detect and contain the intrusion before substantial damage occurs.