A sprawling adversary-in-the-middle (AiTM) phishing campaign is quietly compromising Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services organizations in the US, Canada, and Europe, and it’s doing so without tripping the usual business email compromise (BEC) alarms.
Arctic Wolf Labs disclosed on August 6, 2026, that it has tracked hundreds of targeted organizations in July alone, with confirmed intrusions spanning multiple sectors.
The attack begins with a deceptively simple hook: a fake voicemail notification email, complete with spoofed caller ID, timestamp, and a “Review messages” call-to-action button styled with the Microsoft logo.
New Stealthy AiTM Phishing Campaign
Clicking it triggers a multi-hop redirect chain passing through Google Meet’s link redirector, Google Ads infrastructure, and an AWS S3-hosted page before finally landing on a threat-actor-controlled AiTM proxy that mirrors Microsoft’s real sign-in flow.

Because the proxy relays genuine authentication traffic in real time rather than hosting a static credential form, victims complete MFA challenges normally, and the attacker simply intercepts the resulting session token at the callback stage.
Before serving the fake login page, the toolkit runs victims through a fingerprinting endpoint that harvests browser, OS, screen, WebGL, and WebDriver data likely to filter out security researchers and sandboxes.
It also queries a free geolocation API and stores the victim’s country in a cookie, which Arctic Wolf believes helps operators later select residential proxy exit nodes that geographically match the victim, making follow-on logins look organic.
Rather than immediately draining accounts or rewriting inbox rules, the operators let automation do the work. Compromised sessions are refreshed roughly every 8 hours using rotating residential proxy IPs, often with mismatched combinations like “Mobile Safari on Windows 10,” while retaining the same session ID.
Many sign-ins trigger Microsoft’s rare error code 90014, caused by a missing nonce parameter, giving defenders a high-fidelity but inconsistent signal.

Once inside, the actors use Microsoft Graph to enumerate users tied to payroll, HR, and finance functions, then selectively open not just list emails about invoices, banking, and benefits.
Mailbox access across separate victim organizations sometimes clusters into windows as tight as 26 seconds, pointing to centralized, automated orchestration rather than manual attacker effort.
The campaign’s fingerprinting endpoints, domain-naming patterns, and Graph-based reconnaissance closely mirror the “Payroll Pirates” cluster Microsoft tracks as Storm-2755, alongside related findings from Security Risk Advisors earlier this year. Arctic Wolf’s telemetry suggests the operation’s true footprint extends beyond what was previously reported.
By avoiding classic BEC red flags MFA changes, new device registrations, lateral phishing the actors stay under the radar of behavior-based defenses tuned for smash-and-grab fraud.
Arctic Wolf urges defenders to correlate identity, session, and mailbox telemetry holistically: watching for the eight-hour sign-in cadence, the unique MailItemsAccessed API pairing, and residential proxy anomalies, rather than judging any single login in isolation.
Organizations are advised to deploy phishing-resistant MFA (FIDO2, Windows Hello for Business), enforce device-based Conditional Access, enable Continuous Access Evaluation, and ensure non-interactive sign-in logs are actually being ingested since much of this campaign hides precisely there.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.