Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted hundreds of organizations in the U.S., Canada, and Europe, making the credential theft and session hijacking effort broad enough to affect many enterprises at once.

Related Happenings

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign
H score16 First: 20.08.2026 22:59 Last: 20.08.2026 22:59 Sources 1

About this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...

UNC6671 industrializes vishing credential theft with role-separated labor across extortion brands

Threat Actor Meta
H score47 First: 18.08.2026 19:58 Last: 18.08.2026 19:58 Sources 1

About this happening: UNC6671 is industrializing vishing-driven credential theft with a role-separated labor model that improves scale and reduces insider risk across extortion brands. Its...

Jewelbug multi-region government webmail espionage campaign

Campaign
H score56 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...

Latest development: 14.08.2026 10:54

Broadcom's Symantec and Carbon Black linked Jewelbug's espionage and crypto-fraud operations to XG-Web, a React/Node.js/MySQL control panel used to manage browser-based access, host obfuscated payloads in public Google Docs, and coordinate the com.microsoft.runedge native-messaging host to run operator commands. The analysis also described the malicious PDF Viewer extension for Google Chrome and Mozilla Firefox, and said the campaign targeted government organizations and militaries across the Middle East, Southeast Asia, and South Asia.

15 Government tenants hit by network compromise

Incident
H score50 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity acr...

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

Timeline

  1. 07.08.2026 13:38 2 articles · 13d ago

    Email-driven AitM phishing campaign hijacks Microsoft 365 accounts

    Initial Disclosure

    An active email-driven adversary-in-the-middle phishing campaign is hijacking Microsoft 365 accounts to identify payroll and HR personnel and collect related mailbox data, with hundreds of organizations targeted across the U.S., Canada, and Europe. The activity uses residential proxies and proxied Microsoft authentication to blend malicious sign-ins into ordinary consumer traffic.

    Show sources