Hackers Steal Microsoft 365 Sessions Via Compromised Outlook Accounts
Key Takeaways Attackers are leveraging compromised Microsoft Outlook accounts to launch sophisticated “Adversary-in-the-Middle” (AiTM) phishing attacks. These campaigns specifically...
Key Takeaways
- Attackers are leveraging compromised Microsoft Outlook accounts to launch sophisticated “Adversary-in-the-Middle” (AiTM) phishing attacks.
- These campaigns specifically target multi-factor authenticated (MFA) Microsoft 365 sessions, effectively bypassing MFA protections.
- The threat actors focus on high-value targets including universities, enterprises, and international organizations like those linked to the European Union and United Nations.
- The attack chain involves weaponizing trusted Outlook mailboxes, spoofed login pages, and session cookie hijacking, leading to full account takeover.
- Traditional security measures like MFA and basic domain reputation checks are proving insufficient against these advanced AiTM techniques.
A new wave of sophisticated attacks is exploiting compromised Microsoft Outlook mailboxes, transforming them into stealthy conduits for stealing multi-factor authenticated (MFA) Microsoft 365 sessions. This alarming development means that even users who believe they are protected by robust security measures are vulnerable to session hijacking.
Table Of Content
The technique, known as Adversary-in-the-Middle (AiTM) phishing, has evolved into a highly effective method for seizing active cloud sessions. These sessions are critical for daily organizational operations, making their compromise a significant threat to business continuity and data security. The comprehensive analysis of this threat is detailed in a recent report.
The activity first came to light in May 2026, when a seemingly isolated phishing email distributed to a small group of employees rapidly escalated into a widespread security incident affecting numerous organizations. Once initial accounts were breached, the attackers cleverly repurposed these compromised Outlook mailboxes to propagate the same procurement-themed phishing lures. This allowed them to infiltrate deeper into victim networks and extend their reach to external partners, exploiting established trust relationships.
Analysts at Infoblox successfully traced the origin of these malicious emails back to a broader, ongoing campaign. Their investigation revealed a sophisticated methodology where attackers positioned themselves between users and their legitimate Microsoft 365 login portals, effectively intercepting credentials and session tokens.
Infoblox said in a report shared with Cyber Security News (CSN) that this campaign is not indiscriminate. Instead, it meticulously targets high-value entities, including academic institutions, large corporations, and multinational bodies, notably those associated with the European Union and United Nations.
The phishing lures are crafted to mimic routine business communications, such as requests for proposals, invitations to bid, or shared project documents. This realistic approach makes them exceptionally difficult for busy employees to identify as malicious. A critical aspect of the attack’s success is the use of internal, familiar email addresses for these phishing attempts, transforming trusted communication channels into instruments of compromise.
The original report includes redacted screenshots of these deceptive emails, showcasing their authentic subject lines and the urgent deadlines embedded within them, designed to pressure recipients into hasty decisions. Upon clicking a malicious link, victims are led through a series of fake download pages, CAPTCHA challenges, and meticulously cloned login portals that flawlessly imitate Microsoft 365 and other legitimate services. This sequence feels entirely normal to the user, all while secretly funneling them through attacker-controlled infrastructure.
Hackers Abuse Compromised Outlook Accounts
At the heart of this operation lies advanced AiTM phishing, which weaponizes Outlook itself as a trusted intermediary for Microsoft 365 session theft. After gaining unauthorized access to an initial mailbox, the attackers leverage it to send expertly crafted, procurement-themed emails to both internal and external contacts. This strategy rapidly expands their footprint with each newly compromised account.
When a target clicks the embedded link, they are typically directed to a fabricated document portal hosted on compromised domains such as testserveren[.]com or barifurniture[.]net. These pages are designed to perfectly replicate legitimate file-sharing or procurement platforms, presenting several “shared” files that appear highly relevant to the context of the phishing email. Attempts to download these documents, however, do not deliver the promised content. Instead, they initiate a series of redirects, guiding victims through CAPTCHA prompts and ultimately to spoofed Microsoft 365 login pages.
From the user’s perspective, the process is seamless: they input their email address, complete a CAPTCHA, and sign into Microsoft 365 as they normally would. Unbeknownst to them, behind this facade, reverse proxy kits like EvilProxy, FlowerStorm, and Kali365 are actively relaying their credentials to the authentic Microsoft service. Simultaneously, these tools capture the live session cookies, which represent the user’s fully authenticated state.
The attackers then exploit these stolen cookies to establish authenticated sessions, effectively bypassing any MFA protections that were in place. This grants them unfettered access to Outlook mailboxes, SharePoint files, and a wide array of other Microsoft 365 resources. This precise methodology mirrors other recent AiTM phishing attacks that have successfully targeted Microsoft 365 and Google accounts across various industries, including the notorious Storm 2755 activity.
Once an account is compromised, the attackers frequently perpetuate the cycle by dispatching new phishing emails from the newly hijacked mailbox. This tactic further extends the chain of trust abuse, leveraging the victim’s legitimate identity to ensnare more targets. This approach is reminiscent of modern browser-in-the-middle attacks, which similarly focus on capturing authenticated session states rather than merely stealing raw credentials. The outcome is a rapid and effective intrusion vector that aligns with recent campaigns where AiTM phishing kits provide immediate access to SaaS environments and critical business workflows.
Why MFA and Domain Checks Are Not Enough
This ongoing campaign serves as a stark reminder for cybersecurity defenders: multi-factor authentication alone cannot thwart an attacker who has successfully established an Adversary-in-the-Middle position during the login process. When authentication flows are proxied in real-time, the attacker intercepts and reuses the very session token that signifies successful MFA completion, thereby inheriting the user’s authenticated identity. Similar patterns have been observed in other recent AiTM attack campaigns that bypass MFA for Microsoft 365 and Okta users, often utilizing HR-themed lures and complex layered redirects.
Traditional detection mechanisms, such as domain reputation analysis and URL filtering, also face significant challenges in this scenario. The threat actors often favor older, established domains like testserveren[.]com and barifurniture[.]net, which previously hosted legitimate content and exhibit no suspicious recent registration spikes. Furthermore, many of their phishing pages are served through algorithmically generated (RDGA) domains that feature corporate-sounding names. This tactic aligns with trends seen in “phishing-as-a-service” ecosystems such as Rockstar 2FA and newer kits, as documented in Microsoft’s guidance on defending against advanced AiTM attacks.
What You Should Do
- Implement FIDO2/Hardware-Based MFA: Hardware security keys (e.g., YubiKey) offer the strongest protection against AiTM phishing by cryptographically binding authentication to the originating domain.
- Enhance DNS-Based Threat Intelligence: Integrate advanced DNS visibility and threat intelligence solutions. These can detect subtle indicators like RDGA patterns, anomalous subdomain naming conventions, and infrastructure reuse that remain visible even after specific phishing URLs are taken down.
- Continuous Monitoring of Sign-in Behaviors: Actively monitor Microsoft 365 sign-in logs for unusual activity, such as logins from unfamiliar geographic locations, new devices, or atypical times.
- Enforce Conditional Access Policies: Implement stringent conditional access policies within Microsoft 365 to restrict access based on factors like device compliance, network location, or application sensitivity.
- User Education and Awareness: Regularly train employees on the evolving nature of phishing attacks, emphasizing that even emails from trusted internal sources can be malicious. Highlight the importance of verifying URLs and being suspicious of unexpected requests.
- Review and Audit Session Tokens: Regularly audit active sessions and revoke any suspicious or long-lived session tokens.
- Leverage Microsoft’s Security Features: Utilize Microsoft Defender for Office 365, Azure AD Identity Protection, and other built-in security features designed to detect and mitigate phishing and credential theft.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.