Arctic Wolf Labs has documented an active email-driven phishing campaign that uses adversary-in-the-middle (AitM) techniques to seize control of Microsoft 365 accounts, with the goal of identifying key personnel involved in financial workflows and collecting their payroll and finance-related communications. The campaign is aimed at business-process compromise rather than immediate credential-only theft, according to the security firm’s analysis published August 7.
Arctic Wolf Documents a Microsoft 365 AitM Account Takeover Campaign
The researchers describe a widespread campaign that intercepts sign-ins to Microsoft 365, redirecting victims to credential-harvesting infrastructure that relays tokens and session cookies in real time. The attackers then hold the authenticated sessions open to maintain access to the targeted mailboxes. Observed targets span the healthcare, education, manufacturing, government, and professional services sectors across the United States, Canada, and Europe.
Residential Proxies and Eight-Hour Sessions Mask the Sign-Ins
The campaign relies on residential proxies to disguise malicious sign-ins as ordinary consumer traffic, which helps the operators evade the network-level detections that flag data-center ranges. Once an account is hijacked, the attackers keep the session alive for roughly eight hours with periodic refresh, extending their window to pull financial correspondence from the compromised mailbox. The combination of residential-source IPs and long-lived sessions is what makes the activity difficult to distinguish from legitimate sign-ins in a large tenant.
Storm-2755 “Payroll Pirates” Overlap and the Finance-Focused Targeting
Arctic Wolf observed overlaps between this campaign and known threat clusters tracked as Storm-2755, a group associated with “Payroll Pirates” activity, and Storm-2657. The targeting logic points to organizations whose Microsoft 365 deployments carry payroll and finance workflows, because the operators are after the communications those systems generate — invoices, payment instructions, and bank details — rather than credentials alone.
Why Account Seizure Precedes Financial-Process Compromise
The campaign reflects a shift in credential-phishing objectives: instead of harvesting login data at scale and reselling it, the operators take over the account itself and use it as a vantage point on financial workflows. AitM kits defeat standard multi-factor authentication because they capture the session after the one-time code is entered, so an organization that relies on one-time-passcode MFA has no technical barrier separating the attacker from the mailbox once the sign-in page is spoofed.
Phishing-Resistant MFA and Token Anomaly Monitoring as Countermeasures
No vendor patch applies to this threat, because the entry point is social engineering rather than a software flaw. Arctic Wolf’s guidance directs defenders to enforce phishing-resistant MFA using FIDO2 security keys or passkeys, which cannot be relayed by an AitM proxy, and to monitor for sign-ins originating from residential proxy ranges. Organizations should also validate unusual token issuance and device registration events, which are the fingerprints of a relayed session.
The success of the campaign depends on the point at which an employee types a password into a page that appears to be the Microsoft sign-in portal. Defenders who treat every login prompt as potentially hostile, and who instrument detection around post-authentication anomalies, are better positioned to catch the eight-hour session window before the financial communications leave the tenant. The campaign also shows that finance-focused AitM phishing has moved beyond the consumer credentials market into business-process compromise, where the damage is measured not in passwords but in the payment instructions and bank details an attacker can harvest from a hijacked inbox.
Because the payload is entirely social and requires no software flaw, the threat also makes clear why frictionless single-sign-on is not synonymous with secure single-sign-on. A user who lands on a convincing Microsoft look-alike page and enters credentials has effectively handed the attacker a valid session, and no passive device control short of phishing-resistant MFA reliably intervenes. The eight-hour session persistence, combined with residential-source IPs that look like normal consumer traffic, means a hijacked account can be used to read financial mail over an extended shift before any anomaly is apparent to the tenant’s own monitoring. Arctic Wolf’s guidance to watch token issuance and device registration events, and to enforce FIDO2 or passkey authentication, is the practical counter that keeps the campaign from converting a spoofed page into a business-compromise payment fraud.
