Microsoft 365 AitM phishing campaign using residential proxies
Campaign
Summary
Hide ▲
Show ▼
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted hundreds of organizations in the U.S., Canada, and Europe, making the credential theft and session hijacking effort broad enough to affect many enterprises at once.
Related Happenings
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
H score16
First: 20.08.2026 22:59
Last: 20.08.2026 22:59
Sources 1
About this happening:
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
CampaignAbout this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC6671 industrializes vishing credential theft with role-separated labor across extortion brands
Threat Actor Meta
H score47
First: 18.08.2026 19:58
Last: 18.08.2026 19:58
Sources 1
About this happening:
UNC6671 is industrializing vishing-driven credential theft with a role-separated labor model that improves scale and reduces insider risk across extortion brands. Its...
UNC6671 industrializes vishing credential theft with role-separated labor across extortion brands
Threat Actor MetaAbout this happening: UNC6671 is industrializing vishing-driven credential theft with a role-separated labor model that improves scale and reduces insider risk across extortion brands. Its...
Jewelbug multi-region government webmail espionage campaign
Campaign
H score56
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Jewelbug multi-region government webmail espionage campaign
CampaignAbout this happening: Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Latest development: 14.08.2026 10:54
Broadcom's Symantec and Carbon Black linked Jewelbug's espionage and crypto-fraud operations to XG-Web, a React/Node.js/MySQL control panel used to manage browser-based access, host obfuscated payloads in public Google Docs, and coordinate the com.microsoft.runedge native-messaging host to run operator commands. The analysis also described the malicious PDF Viewer extension for Google Chrome and Mozilla Firefox, and said the campaign targeted government organizations and militaries across the Middle East, Southeast Asia, and South Asia.
15 Government tenants hit by network compromise
Incident
H score50
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity acr...
15 Government tenants hit by network compromise
IncidentAbout this happening: The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity acr...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
H score40
First: 04.08.2026 20:27
Last: 04.08.2026 20:27
Sources 1
About this happening:
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor MetaAbout this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Timeline
-
07.08.2026 13:38 2 articles · 13d ago
Email-driven AitM phishing campaign hijacks Microsoft 365 accounts
Initial DisclosureAn active email-driven adversary-in-the-middle phishing campaign is hijacking Microsoft 365 accounts to identify payroll and HR personnel and collect related mailbox data, with hundreds of organizations targeted across the U.S., Canada, and Europe. The activity uses residential proxies and proxied Microsoft authentication to blend malicious sign-ins into ordinary consumer traffic.
Show sources
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails — thehackernews.com — 07.08.2026 13:38
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails — thehackernews.com — 07.08.2026 13:38