logo

Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign

ID: ec9c1792-662d-530b-9109-2518c5ef9284

STIX ID: report--ec9c1792-662d-530b-9109-2518c5ef9284

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-24

Date Updated: 2026-04-21

Author: Dhivya

...
...

Microsoft Defender disclosed a sophisticated AiTM phishing campaign targeting energy sector organisations by abusing SharePoint links from a compromised vendor account to harvest credentials and session cookies, then establishing persistence (malicious inbox rules, MFA manipulation) and conducting mass BEC operations across multiple organisations; Microsoft published two IP IoCs and recommended revoking session cookies, removing inbox rules, resetting MFA, and implementing conditional access and advanced anti-phishing defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.