How Hackers Are Using AitM Phishing to Steal Payroll Emails from Microsoft 365

ยท
Listen to this article~6 min
How Hackers Are Using AitM Phishing to Steal Payroll Emails from Microsoft 365

AitM phishing is bypassing MFA to hijack Microsoft 365 accounts, targeting payroll and finance emails. Learn how attackers use residential proxies and how to defend your team.

You might think your Microsoft 365 account is safe because you use two-factor authentication. But there's a new phishing wave that's clever enough to get around that. Cybersecurity researchers have flagged an active, widespread email campaign that uses adversary-in-the-middle (AitM) techniques to take over Microsoft 365 accounts. The goal? To pinpoint the people in your company who handle payroll and finance, then quietly siphon off their emails. This isn't your run-of-the-mill phishing. The attackers are using residential proxies to make their malicious sign-ins look like ordinary consumer traffic. That means their activity blends right in with the noise of everyday internet use, making it much harder for security tools to spot the threat. ### Why Payroll and Finance Emails Are the Target Think about what sits in a finance team's inbox. Bank transfer confirmations, vendor payment details, tax documents, and employee salary records. It's a goldmine for a cybercriminal. By hijacking a Microsoft 365 account, they don't just get one piece of information. They get a continuous stream of sensitive data, often without the victim knowing anything is wrong. What's more, the attackers are specifically looking for key personnel. They're not casting a wide net and hoping for the best. They're identifying who in the organization is responsible for financial workflows. Once they know that, they can tailor their next moves, which might include invoice fraud, wire transfer interception, or even a follow-up BEC (business email compromise) attack. ### How the AitM Attack Works AitM phishing is a step up from classic phishing. Here's the simplified version: you get an email that looks legitimate, asking you to log in to a familiar service. When you click the link, you're actually sent to a proxy server that sits between you and the real Microsoft 365 login page. This proxy passes your request through to the genuine site, so you see the real login screen. When you enter your credentials, the proxy captures them before they reach Microsoft. It also grabs your session cookie, which is the digital pass that keeps you logged in. With that cookie, the attacker can access your account even after you've walked away from your desk. ### The Role of Residential Proxies in Evading Detection Residential proxies are a key part of this campaign. These are IP addresses that belong to real homes and real internet service providers. When the attacker uses one, their traffic appears to come from a normal household, not a data center or a known malicious server. Because of that, security systems that rely on IP reputation often don't raise any red flags. It's like a burglar using a key that belongs to a neighbor. The lock looks normal, the key fits, and no one thinks to ask questions. ### What You Can Do to Protect Your Organization If you're responsible for security at your company, here are a few practical steps to lower your risk: - **Enforce conditional access policies** that require device compliance, not just a password and a one-time code. - **Use phishing-resistant MFA**, like FIDO2 security keys, instead of SMS or authenticator apps that can be intercepted. - **Monitor for impossible travel** โ€“ if a user logs in from New York and then from London five minutes later, that's a red flag. - **Train your finance team specifically** about AitM attacks. They're the primary target, and they need to know what to look for. - **Review sign-in logs regularly** for unusual session activity, especially around payroll dates. ### Staying Ahead of the Threat This campaign is a reminder that attackers are always evolving. They're investing in infrastructure like residential proxies and building sophisticated tools to bypass the defenses that used to work. The good news is that awareness is a powerful defense. The more you know about how these attacks operate, the better you can prepare your team and your systems. Don't wait for a breach to take action. Audit your current MFA setup, talk to your finance department, and make sure your security team knows about AitM phishing. A few proactive steps today could prevent a serious data leak tomorrow. If you're involved in managing multiple accounts or running operations that require a higher level of anonymity, you might also want to explore how an antidetect browser can add an extra layer of separation between your personal identity and your online activities. It's not a replacement for strong security practices, but it can be a useful tool in the right context.