logo

Ongoing campaign compromises senior execs’ Azure accounts, locks them using MFA

ID: 828a7f60-b553-5963-96ba-d7cb15d2c07e

STIX ID: report--828a7f60-b553-5963-96ba-d7cb15d2c07e

Feed Name: Proofpoint Blog

Threat Score
65/100

Date Published: 2024-02-12

Date Updated: 2026-04-28

...
...

Proofpoint warns of an ongoing campaign performing Microsoft 365 account takeovers where attackers use proxy services (and sometimes local ISPs), compromised domains, and mailbox rule obfuscation to evade detection and align geolocation with targets. The report provides IOCs — specific user-agent strings, a list of malicious domains and implicated ISPs — and recommends monitoring sign-in user agents and source domains, detecting post-compromise mailbox activity, and applying rapid remediation and anti-phishing controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.