"The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic," Arctic Wolf Labs said.
Arctic Wolf Labs: scope, sectors, and financial intent
Security researchers at Arctic Wolf Labs reported a "widespread email-driven phishing campaign" that has successfully hijacked Microsoft 365 accounts at scale. The firm said it observed hundreds of organizations targeted by email last month and confirmed successful intrusions across a broad range of victim environments. Affected sectors include healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe.
The intrusions are financially focused: attackers seek to identify personnel involved in payroll, HR, finance, and administrative workflows and to collect related mailbox data. Arctic Wolf noted tactical overlap with attacks Microsoft has tracked under the Payroll Pirate designation (Storm-2755) and with earlier activity recorded as Storm-2657.
Six-stage redirection: Google Meet to Amazon S3 to an AitM proxy
The campaign begins with voicemail-themed phishing emails that lure victims through a multi-step redirect chain. Arctic Wolf described a six-stage flow that deliberately leverages legitimate services to evade reputation filters: a Google Meet linkredirect URL, Google's outbound-link infrastructure, a Campaign Manager /ddm/clk dynamic click tracker, and an HTML object hosted in an Amazon S3 bucket that ultimately redirects to the campaign's adversary-in-the-middle (AitM) phishing infrastructure.
Those AitM decoy pages act as a proxy for the legitimate Microsoft account authentication flow. The pages also run JavaScript to fingerprint visiting hosts—collecting browser and operating-system details, screen and window dimensions, browser language, time zone offset, cookie capabilities, WebDriver status, WebGL vendor, and browser API availability—and POST that data to a PHP endpoint before redirecting the browser to the proxied Microsoft OAuth authorization endpoint.
The phishing pages also query a geolocation API ("api.country[.]is") to obtain a country code and store it in a "rcfh_country" cookie with a seven-day expiration, indicating the operators are gathering geolocation data to inform subsequent actions.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSession persistence via rotating residential proxies and centralized automation
Arctic Wolf's analysis shows the attackers use residential proxy exit nodes that appear in the victim's country. Initial malicious sign-ins can originate within minutes from such nodes. In many cases, 11 to 24 hours after that first anomalous activity, malicious sign-ins recur at approximately eight-hour intervals from rotating residential proxy addresses.
These recurring sign-ins reported Microsoft Outlook as the client application but used user agents such as Firefox 131.0, Firefox 151.0, or occasionally Python Requests—rather than the expected Edge user agent. Some sign-ins showed "implausible browser and operating-system combinations," for example mobile versions of Apple Safari or Google Chrome on Windows 10. The recurring sign-ins retained the same SessionID while source IP address, ASN, and geographic location changed, which Arctic Wolf said provided "further evidence that centralized automation was refreshing each compromised session independently."
In most intrusions the attackers restricted activity to session maintenance, reconnaissance, and mailbox collection; Arctic Wolf reported no observed MFA-method changes, device registrations, credential modifications, lateral phishing, or mass inbox-rule creation in the majority of cases. That restraint—combined with delayed automation after initial access—reduces signals that commonly trigger detections.
Microsoft Graph API enumeration and mailbox collection
As with other Payroll Pirates activity, the operators were observed using the Microsoft Graph API to enumerate tenant users tied to payroll, HR, finance, and administrative roles and then accessing messages related to payroll, invoices, payments, banking, benefits, and internal documents. While most activity was automated, Arctic Wolf noted a handful of cases where operators performed hands-on keyboard actions: selectively creating inbox rules that moved messages from Inbox to Deleted Items and marked them as read.
How security teams, enterprises, and end users are affected
- Security teams and technologists: Monitor for recurring sign-in events that show SessionID persistence alongside changing IP/ASN/geolocation, unusual user-agent strings (Firefox or Python Requests where Edge would be expected), and Graph API enumeration patterns targeting payroll/HR groups. Watch for voicemail-themed emails that initiate Google Meet linkredirects and long redirection chains through trusted services.
- Affected enterprises and procurement leaders: Payroll, HR, finance, and administrative mailboxes are primary targets. The campaign's use of legitimate services (Google, Campaign Manager, Amazon S3) to host redirectors and proxies can defeat reputation-based filters and complicate incident triage across multiple cloud providers and service logs.
- End users: The phishing lures mimic voicemail notifications and lead to decoy Microsoft sign-in flows that can capture credentials and multi-factor authentication codes. Arctic Wolf's findings underscore that MFA codes and credentials can be harvested in real time via AitM proxies.
Arctic Wolf's report draws a clear line between low-noise, automated session maintenance and targeted mailbox collection: by avoiding obvious account changes and waiting before automated harvesting begins, operators make it harder to connect the theft of payroll and financial emails back to the original phishing event. That restraint is the story's central risk—one that leaves enterprise defenders looking for subtle artifacts (SessionID reuse across rotating residential proxies, implausible client strings, Graph API queries against finance and HR groups) rather than loud, conventional signals.
https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html



