Sophisticated AiTM Phishing Campaign Hijacks Microsoft 365 Sessions via Compromised Outlook Accounts
In May 2026, security researchers at Infoblox uncovered a highly targeted adversary-in-the-middle (AiTM) phishing campaign abusing Microsoft Outlook mailboxes to steal multi-factor authenticated (MFA) Microsoft 365 sessions. The attack, which began with a single phishing email sent to a small group of employees, rapidly escalated into a cross-organizational compromise, leveraging trusted internal communication channels to spread.
How the Attack Works
- Initial Compromise – Attackers send procurement-themed phishing emails (e.g., RFIs, bid invitations, or shared documents) from compromised Outlook accounts, making them appear legitimate to recipients.
- Fake Portals & Cloned Logins – Victims who click embedded links are redirected through compromised domains (e.g., testserveren[.]com, barifurniture[.]net) to fake document portals and spoofed Microsoft 365 login pages.
- Session Hijacking – Using reverse proxy kits like EvilProxy, FlowerStorm, and Kali365, attackers intercept credentials and live session cookies, bypassing MFA and gaining full access to Outlook, SharePoint, and Microsoft 365 resources.
- Lateral Movement – Once inside, attackers reuse compromised mailboxes to send new phishing emails, extending the attack chain to internal teams and external partners.
Targets & Tactics
The campaign focuses on high-value organizations, including:
- Universities
- Enterprises
- Multinational institutions (e.g., EU and UN-linked bodies)
Phishing emails mimic routine business workflows, using urgent deadlines and familiar sender addresses to evade suspicion. Attackers exploit aged, legitimate-looking domains (e.g., testserveren[.]com) to bypass domain reputation checks, while RDGA-generated domains (e.g., consistenthostinghub[.]de) further obscure detection.
Impact & Broader Threat Landscape
- Full Identity Inheritance – Stolen session cookies grant attackers authenticated access to email, files, and SaaS applications, enabling payroll fraud, data exfiltration, and further account takeovers.
- MFA Bypass – Since attackers proxy authentication flows in real time, MFA protections are rendered ineffective.
- Industry-Wide Trend – This campaign aligns with Storm-2755 and other AiTM attacks, where threat actors prioritize session hijacking over credential theft for deeper, persistent access.
Detection Challenges & Defensive Insights
Traditional defenses MFA, URL filtering, and domain reputation checks struggle against these attacks. Infoblox recommends:
- DNS-based threat intelligence to detect infrastructure reuse and subdomain patterns.
- Continuous monitoring of Microsoft 365 sign-in behaviors to identify anomalous session activity.
- Conditional access policies to limit the lifespan of stolen sessions.
Indicators of Compromise (IoCs)
Key domains linked to the campaign include:
- Compromised hosting domains: barifurniture[.]net, testserveren[.]com, satoriestate[.]com
- Phishing infrastructure: consistenthostinghub[.]de (FlowerStorm), assessmentevaluationreport[.]com (EvilProxy), duemineral[.]uk (Kali365)
The attack underscores the evolving sophistication of AiTM phishing, where trusted communication channels become attack vectors, and session-based compromises outpace traditional credential theft.
Source: https://cybersecuritynews.com/hackers-compromised-outlook-accounts/
Infoblox cybersecurity rating report: https://www.rankiteo.com/company/infoblox
"id": "INF1784716085",
"linkid": "infoblox",
"type": "Cyber Attack",
"date": "5/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Education, Corporate, Government-linked '
'(EU, UN)',
'type': 'Universities, Enterprises, Multinational '
'institutions'}],
'attack_vector': 'Compromised Outlook accounts, phishing emails, reverse '
'proxy kits (EvilProxy, FlowerStorm, Kali365)',
'data_breach': {'data_exfiltration': 'Possible (not explicitly confirmed)',
'personally_identifiable_information': 'Likely (emails, '
'corporate data)',
'sensitivity_of_data': 'High (PII, corporate communications, '
'sensitive documents)',
'type_of_data_compromised': 'Session cookies, credentials, '
'emails, files, SaaS application '
'access'},
'date_detected': '2026-05',
'date_publicly_disclosed': '2026-05',
'description': 'In May 2026, security researchers at Infoblox uncovered a '
'highly targeted adversary-in-the-middle (AiTM) phishing '
'campaign abusing Microsoft Outlook mailboxes to steal '
'multi-factor authenticated (MFA) Microsoft 365 sessions. The '
'attack began with a single phishing email sent to a small '
'group of employees and rapidly escalated into a '
'cross-organizational compromise, leveraging trusted internal '
'communication channels to spread.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'trusted channel abuse',
'data_compromised': 'Microsoft 365 session cookies, credentials, '
'Outlook emails, SharePoint files, SaaS '
'application access',
'identity_theft_risk': 'High (full identity inheritance via '
'session cookies)',
'operational_impact': 'Lateral movement within organizations, '
'cross-organizational compromise, trusted '
'communication abuse',
'payment_information_risk': 'Potential (payroll fraud)',
'systems_affected': 'Microsoft 365 (Outlook, SharePoint), internal '
'communication channels'},
'initial_access_broker': {'backdoors_established': 'Reverse proxy kits '
'(EvilProxy, FlowerStorm, '
'Kali365)',
'entry_point': 'Phishing emails from compromised '
'Outlook accounts',
'high_value_targets': 'Universities, enterprises, '
'multinational institutions '
'(EU/UN-linked)'},
'investigation_status': 'Ongoing (as of disclosure)',
'lessons_learned': 'Traditional defenses (MFA, URL filtering, domain '
'reputation) are insufficient against AiTM attacks. '
'Session-based compromises require continuous monitoring '
'and conditional access policies to limit stolen session '
'lifespans.',
'motivation': 'Data exfiltration, payroll fraud, account takeover, lateral '
'movement',
'post_incident_analysis': {'corrective_actions': 'DNS-based threat detection, '
'Microsoft 365 behavior '
'monitoring, conditional '
'access policies',
'root_causes': 'Abuse of trusted communication '
'channels, session hijacking via '
'reverse proxies, lack of '
'conditional access policies'},
'recommendations': ['Implement DNS-based threat intelligence to detect '
'infrastructure reuse and subdomain patterns.',
'Monitor Microsoft 365 sign-in behaviors for anomalous '
'session activity.',
'Enforce conditional access policies to limit the '
'lifespan of stolen sessions.'],
'references': [{'source': 'Infoblox'}],
'response': {'enhanced_monitoring': 'DNS-based threat intelligence, Microsoft '
'365 sign-in behavior monitoring',
'third_party_assistance': 'Infoblox (security researchers)'},
'threat_actor': 'Storm-2755 (suspected)',
'title': 'Sophisticated AiTM Phishing Campaign Hijacks Microsoft 365 Sessions '
'via Compromised Outlook Accounts',
'type': 'Phishing (AiTM)',
'vulnerability_exploited': 'Session hijacking via stolen MFA-authenticated '
'session cookies, lack of conditional access '
'policies'}