Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
ID: f6e137d5-dcb4-5f2a-b4de-9663e949fdab
STIX ID: report--f6e137d5-dcb4-5f2a-b4de-9663e949fdab
Feed Name: cybersecurityNews.com
This report details an active AiTM phishing campaign (surfaced May 2026) in which attackers compromise Microsoft Outlook mailboxes to send procurement-themed lures that lead victims to fake download pages and cloned Microsoft 365 login portals; reverse-proxy kits capture live session cookies to bypass MFA and enable account takeover, with numerous domain IoCs and infrastructure tied to EvilProxy, FlowerStorm and Kali365 listed, and victims including universities, enterprises and multinational institutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
