A sophisticated phishing campaign is actively compromising Microsoft 365 accounts by leveraging adversary-in-the-middle (AitM) techniques and residential proxy networks to bypass conventional multi-factor authentication. As reported by The Hacker News on 7 August 2026, this operation moves beyond broad data theft to focus on corporate email infiltration, specifically mapping financial personnel and harvesting communications related to payroll, vendor payments, and accounts payable.
The attack initiates with carefully crafted phishing links that redirect victims through a threat actor-controlled proxy. This setup enables real-time interception of authentication requests, capturing both credentials and active session cookies. The stolen tokens are then relayed to Microsoft's legitimate login infrastructure, effectively neutralizing standard MFA prompts. To mask these malicious activities, the attackers route traffic through residential IP addresses, blending compromised logins seamlessly with ordinary consumer internet traffic.
Security researchers highlight that this campaign marks a strategic shift from opportunistic credential harvesting to intelligence-driven reconnaissance. Once inside a Microsoft 365 tenant, threat actors quietly scan inboxes and contact lists to identify employees with financial authority. The ultimate goal is often business email compromise (BEC), where stolen trust and internal communication patterns are exploited to authorize fraudulent wire transfers or alter payment details.
For IT and security teams, this campaign exposes critical gaps in traditional perimeter defenses. Standard password policies and push-notification MFA prove ineffective against session-aware AitM attacks. Experts advocate for a layered defense-in-depth strategy centered on rigorous session lifecycle management. Key recommendations include enforcing strict conditional access policies, restricting authentication to managed devices, and shortening session token lifetimes to reduce token replay opportunities. Additionally, deploying continuous authentication monitoring can flag anomalous logins from unusual geographic locations or known residential proxy ranges.
The implementation of such measures presents operational challenges. Aggressive session timeouts may introduce user friction, while detecting AitM infrastructure in real time demands advanced behavioral analytics that many enterprises have yet to fully adopt. Consequently, procedural safeguards become essential last lines of defense. Mandating out-of-band verification—such as a separate phone call—for any changes to banking details or payroll configurations, particularly among finance and HR staff, can disrupt fraud even if an account is compromised.
Looking ahead, security architects stress the urgency of adopting phishing-resistant authentication standards like FIDO2 security keys, which are inherently immune to AitM interception. Until these controls achieve widespread deployment, maintaining vigilant session monitoring and enforcing strict financial verification protocols will be critical to countering this evolving threat.
一個精密的釣魚攻擊活動正利用中間人對手(Adversary-in-the-Middle, AitM)技術及住宅代理網絡,積極入侵Microsoft 365帳戶,藉此繞過傳統的多重驗證機制。據The Hacker News於2026年8月7日報導,此行動已超越廣泛的數據竊取,轉而專注於企業電郵滲透,具體針對財務人員進行定位,並收割與薪資、供應商付款及應付帳款相關的通訊。
攻擊始於精心設計的釣魚連結,將受害者重定向至攻擊者控制的代理服務器。此設定能即時攔截驗證請求,同時捕獲登入憑證及有效會話Cookie。被盜取的權杖隨後被轉發至Microsoft的合法登入基礎設施,有效規避標準的多重驗證提示。為掩蓋這些惡意活動,攻擊者透過住宅IP地址路由流量,使被入侵的登入行為能毫無痕跡地混入普通用戶的互聯網流量中。
安全研究人員指出,此次攻擊活動標誌著從機會式憑證收集到情報驅動偵察的策略轉變。一旦進入Microsoft 365租戶,威脅行為者會靜默掃描收件匣及聯絡人名單,以識別具備財務權限的員工。最終目的通常是商業電郵欺詐(Business Email Compromise, BEC),利用被盜取的信任關係及內部溝通模式,來授權欺詐性電匯或篡改付款細節。
對IT及安全團隊而言,此攻擊活動暴露了傳統邊界防禦的關鍵缺口。標準密碼策略及推送通知式多重驗證,對具備會話感知能力的AitM攻擊證明無效。專家提倡採用以嚴格會話生命週期管理為核心的縱深防禦策略。主要建議包括實施嚴格的條件式存取政策、將驗證限制於受管理設備、以及縮短會話權杖的有效期以減少權杖重用機會。此外,部署持續驗證監控能標記來自異常地理位置或已知住宅代理範圍的異常登入行為。
這些措施的實施帶來運營挑戰。過於激進的會話逾時機制可能增加用戶摩擦,而即時偵測AitM基礎設施則需倚賴許多企業尚未全面採用的高階行為分析技術。因此,程序性保障措施成為關鍵的最後防線。針對任何銀行細節或薪資設定的變更,特別是財務及人力資源員工之間,強制要求帶外驗證——例如另行電話確認——即使帳戶已被入侵,也能有效阻斷欺詐行為。
展望未來,安全架構師強調迫切需要採用抗釣魚的驗證標準,例如FIDO2安全金鑰,其技術原理能免疫AitM攔截。在這些控制措施廣泛普及之前,維持警覺的會話監控及嚴格的財務驗證協議,將成為應對此持續演變威脅的關鍵。
