logo

Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users

ID: d181c77b-8971-58f8-853e-0e77322d81c7

STIX ID: report--d181c77b-8971-58f8-853e-0e77322d81c7

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2025-12-10

Date Updated: 2026-04-27

...
...

### Executive summary Datadog Security Labs reports an active, sophisticated phishing campaign that hijacks Microsoft 365 and Okta SSO flows by proxying legitimate login pages and injecting JavaScript to steal credentials and session cookies; the attack uses lookalike Okta domains and weaponized Microsoft login pages that redirect victims to second-stage Okta phishing pages, leverages Cloudflare infrastructure and link shorteners, and uses an "employee benefits" lure — the report includes code samples, IOCs (domains, email subjects, senders), and detection queries for Okta and Microsoft 365 logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.