Microsoft 365 AitM Phishing Targets Payroll Workflows
🔍 Arctic Wolf Labs warns of a widespread email-driven phishing campaign using adversary-in-the-middle (AitM) techniques to seize Microsoft 365 sessions and harvest payroll and HR email. The campaign leverages residential proxies, multi-step redirections through trusted services, and fingerprinting scripts to evade filters and maintain compromised sessions at roughly eight-hour intervals. Affected sectors include healthcare, education, manufacturing, government, and professional services across the U.S., Canada, and Europe.
