Arctic Wolf Labs is tracking an active adversary-in-the-middle (AiTM) phishing campaign compromising Microsoft 365 accounts across multiple sectors and regions. The campaign uses voicemail-themed phishing emails with multi-stage redirect chains through legitimate services (Google Meet, Google Ads, AWS S3) to reach AiTM proxy domains that relay Microsoft authentication and intercept session tokens even when MFA is enabled. Stolen sessions are maintained via automated 8-hour sign-in cadences from rotating residential proxies, followed by Microsoft Graph reconnaissance of payroll/HR/finance personnel and coordinated mailbox collection. The campaign shares characteristics with Microsoft's Storm-2755 (Payroll Pirates) cluster and avoids traditional BEC behaviors to evade detection.
AiTM Phishing
8 posts
Payroll Pirates: Strange New Tides in Business Email Compromise UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments UNC6671 is an active extortion group that has expanded operations across five brands (BlackFile, Redact, Pink, Helix, Falcon) despite announcing BlackFile's retirement in May 2026. The group consistently uses IT helpdesk voice phishing (vishing) to target employees on personal mobile devices, directing them to Adversary-in-the-Middle (AiTM) credential harvesting panels hosted on passkey-themed domains. Stolen sessions are used to deploy automated scripts exfiltrating data from Microsoft 365 and Okta environments. Shared infrastructure, identical phishing templates, and overlapping victim targeting across all brands indicate a coordinated group. Recent targeting has narrowed to financial services, private equity, and legal sectors, with ransom demands ranging from $1M to $3M USD and final payments averaging approximately $750,000.
How legitimate cloud platforms enable phishers to bypass MFA Threat actors are systematically abusing legitimate cloud PaaS platforms and IPFS gateways to host multi-stage adversary-in-the-middle (AitM) phishing infrastructure that bypasses MFA. The attack chain uses compromised websites as disposable relays, Cloudflare Workers for core phishing content, browser service workers with the Ultraviolet proxy library to intercept all tab network traffic, and Browser-in-the-Browser (BitB) spoofing to display trusted URLs while silently capturing credentials and session tokens. Over 390,000 phishing pages on legitimate cloud platforms were identified in 12 months, with reputation-based blocklists proving ineffective against programmatically generated subdomains on trusted apex domains.
Building Resilience Against AiTM Phishing: What SOC Leaders Should Know The article discusses how modern adversary-in-the-middle (AiTM) phishing attacks increasingly operate entirely within encrypted browser sessions, leaving little to no artifacts in files or processes, thereby evading traditional file-centric detection tools. It advocates for browser-level visibility, SSL/TLS decryption of session traffic, and threat-intelligence pivoting to detect and investigate such campaigns, illustrating the approach with screenshots of a live fake-CAPTCHA phishing chain and related infrastructure/hashes pulled from a threat intelligence feed.
The Procurement Trap: Inside an AiTM Campaign Targeting Global Institutions An adversary-in-the-middle (AiTM) phishing campaign is targeting global institutions including EU and UN agencies using procurement-themed lures sent from compromised organizational email accounts. The actor rotates between multiple AiTM phishing kits (EvilProxy, FlowerStorm/Storm-1167, Kali365) and uses aged, likely compromised domains injected with PHP to host fake document download portals. By proxying authentication flows in real time, the attacker captures session tokens and cookies after MFA completion, bypassing identity controls and inheriting the victim's authenticated session.
Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk Kratos is a mature Phishing-as-a-Service operation impersonating Microsoft 365 login pages to steal credentials across US and European organizations. The kit uses legitimate platforms (SharePoint, Canva, Tilda) as intermediary redirect pages, Cloudflare Turnstile to block automated analysis, and PHP endpoints for credential exfiltration. Researchers identified three generations (V0, V1, V2) with distinct asset fingerprints and exfiltration code, and uncovered the operator panel with automated deployment, Telegram-based data delivery, and geographic restriction capabilities.
US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data ANY.RUN's Malware Trends Tracker data shows that phishing-as-a-service kits now dominate the US threat landscape, with five of the top ten threats being AiTM or device-code phishing platforms that defeat MFA by stealing session cookies or OAuth tokens. Commodity RATs and info stealers remain in constant high-volume circulation, while legacy threats like Emotet and WannaCry persist on unpatched systems. Several top-ranked threats (Cobalt Strike, Qbot, Emotet, DonutLoader, Smoke Loader) function as ransomware precursors, meaning their detection should trigger urgent escalation rather than routine handling.
The Unintentional Enabler: How Cloudflare Services are Abused for Credential Theft and Malware Distribution Threat actors are actively abusing legitimate Cloudflare services, specifically Workers and Tunnels, to conduct adversary-in-the-middle (AiTM) phishing and distribute malware. By leveraging Cloudflare's trusted infrastructure and free tiers, attackers successfully bypass traditional security controls to deliver remote access trojans like Xeno RAT and XWorm RAT via obfuscated WebDAV connections.