Infoblox: Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions

Infoblox: Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions

Sophisticated AiTM Phishing Campaign Hijacks Microsoft 365 Sessions via Compromised Outlook Accounts

In May 2026, security researchers at Infoblox uncovered a highly targeted adversary-in-the-middle (AiTM) phishing campaign abusing Microsoft Outlook mailboxes to steal multi-factor authenticated (MFA) Microsoft 365 sessions. The attack, which began with a single phishing email sent to a small group of employees, rapidly escalated into a cross-organizational compromise, leveraging trusted internal communication channels to spread.

How the Attack Works

  1. Initial Compromise – Attackers send procurement-themed phishing emails (e.g., RFIs, bid invitations, or shared documents) from compromised Outlook accounts, making them appear legitimate to recipients.
  2. Fake Portals & Cloned Logins – Victims who click embedded links are redirected through compromised domains (e.g., testserveren[.]com, barifurniture[.]net) to fake document portals and spoofed Microsoft 365 login pages.
  3. Session Hijacking – Using reverse proxy kits like EvilProxy, FlowerStorm, and Kali365, attackers intercept credentials and live session cookies, bypassing MFA and gaining full access to Outlook, SharePoint, and Microsoft 365 resources.
  4. Lateral Movement – Once inside, attackers reuse compromised mailboxes to send new phishing emails, extending the attack chain to internal teams and external partners.

Targets & Tactics

The campaign focuses on high-value organizations, including:

  • Universities
  • Enterprises
  • Multinational institutions (e.g., EU and UN-linked bodies)

Phishing emails mimic routine business workflows, using urgent deadlines and familiar sender addresses to evade suspicion. Attackers exploit aged, legitimate-looking domains (e.g., testserveren[.]com) to bypass domain reputation checks, while RDGA-generated domains (e.g., consistenthostinghub[.]de) further obscure detection.

Impact & Broader Threat Landscape

  • Full Identity Inheritance – Stolen session cookies grant attackers authenticated access to email, files, and SaaS applications, enabling payroll fraud, data exfiltration, and further account takeovers.
  • MFA Bypass – Since attackers proxy authentication flows in real time, MFA protections are rendered ineffective.
  • Industry-Wide Trend – This campaign aligns with Storm-2755 and other AiTM attacks, where threat actors prioritize session hijacking over credential theft for deeper, persistent access.

Detection Challenges & Defensive Insights

Traditional defenses MFA, URL filtering, and domain reputation checks struggle against these attacks. Infoblox recommends:

  • DNS-based threat intelligence to detect infrastructure reuse and subdomain patterns.
  • Continuous monitoring of Microsoft 365 sign-in behaviors to identify anomalous session activity.
  • Conditional access policies to limit the lifespan of stolen sessions.

Indicators of Compromise (IoCs)

Key domains linked to the campaign include:

  • Compromised hosting domains: barifurniture[.]net, testserveren[.]com, satoriestate[.]com
  • Phishing infrastructure: consistenthostinghub[.]de (FlowerStorm), assessmentevaluationreport[.]com (EvilProxy), duemineral[.]uk (Kali365)

The attack underscores the evolving sophistication of AiTM phishing, where trusted communication channels become attack vectors, and session-based compromises outpace traditional credential theft.

Source: https://cybersecuritynews.com/hackers-compromised-outlook-accounts/

Infoblox cybersecurity rating report: https://www.rankiteo.com/company/infoblox

"id": "INF1784716085",
"linkid": "infoblox",
"type": "Cyber Attack",
"date": "5/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Education, Corporate, Government-linked '
                                    '(EU, UN)',
                        'type': 'Universities, Enterprises, Multinational '
                                'institutions'}],
 'attack_vector': 'Compromised Outlook accounts, phishing emails, reverse '
                  'proxy kits (EvilProxy, FlowerStorm, Kali365)',
 'data_breach': {'data_exfiltration': 'Possible (not explicitly confirmed)',
                 'personally_identifiable_information': 'Likely (emails, '
                                                        'corporate data)',
                 'sensitivity_of_data': 'High (PII, corporate communications, '
                                        'sensitive documents)',
                 'type_of_data_compromised': 'Session cookies, credentials, '
                                             'emails, files, SaaS application '
                                             'access'},
 'date_detected': '2026-05',
 'date_publicly_disclosed': '2026-05',
 'description': 'In May 2026, security researchers at Infoblox uncovered a '
                'highly targeted adversary-in-the-middle (AiTM) phishing '
                'campaign abusing Microsoft Outlook mailboxes to steal '
                'multi-factor authenticated (MFA) Microsoft 365 sessions. The '
                'attack began with a single phishing email sent to a small '
                'group of employees and rapidly escalated into a '
                'cross-organizational compromise, leveraging trusted internal '
                'communication channels to spread.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'trusted channel abuse',
            'data_compromised': 'Microsoft 365 session cookies, credentials, '
                                'Outlook emails, SharePoint files, SaaS '
                                'application access',
            'identity_theft_risk': 'High (full identity inheritance via '
                                   'session cookies)',
            'operational_impact': 'Lateral movement within organizations, '
                                  'cross-organizational compromise, trusted '
                                  'communication abuse',
            'payment_information_risk': 'Potential (payroll fraud)',
            'systems_affected': 'Microsoft 365 (Outlook, SharePoint), internal '
                                'communication channels'},
 'initial_access_broker': {'backdoors_established': 'Reverse proxy kits '
                                                    '(EvilProxy, FlowerStorm, '
                                                    'Kali365)',
                           'entry_point': 'Phishing emails from compromised '
                                          'Outlook accounts',
                           'high_value_targets': 'Universities, enterprises, '
                                                 'multinational institutions '
                                                 '(EU/UN-linked)'},
 'investigation_status': 'Ongoing (as of disclosure)',
 'lessons_learned': 'Traditional defenses (MFA, URL filtering, domain '
                    'reputation) are insufficient against AiTM attacks. '
                    'Session-based compromises require continuous monitoring '
                    'and conditional access policies to limit stolen session '
                    'lifespans.',
 'motivation': 'Data exfiltration, payroll fraud, account takeover, lateral '
               'movement',
 'post_incident_analysis': {'corrective_actions': 'DNS-based threat detection, '
                                                  'Microsoft 365 behavior '
                                                  'monitoring, conditional '
                                                  'access policies',
                            'root_causes': 'Abuse of trusted communication '
                                           'channels, session hijacking via '
                                           'reverse proxies, lack of '
                                           'conditional access policies'},
 'recommendations': ['Implement DNS-based threat intelligence to detect '
                     'infrastructure reuse and subdomain patterns.',
                     'Monitor Microsoft 365 sign-in behaviors for anomalous '
                     'session activity.',
                     'Enforce conditional access policies to limit the '
                     'lifespan of stolen sessions.'],
 'references': [{'source': 'Infoblox'}],
 'response': {'enhanced_monitoring': 'DNS-based threat intelligence, Microsoft '
                                     '365 sign-in behavior monitoring',
              'third_party_assistance': 'Infoblox (security researchers)'},
 'threat_actor': 'Storm-2755 (suspected)',
 'title': 'Sophisticated AiTM Phishing Campaign Hijacks Microsoft 365 Sessions '
          'via Compromised Outlook Accounts',
 'type': 'Phishing (AiTM)',
 'vulnerability_exploited': 'Session hijacking via stolen MFA-authenticated '
                            'session cookies, lack of conditional access '
                            'policies'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.