logo

Resurgence of a multi‑stage AiTM phishing and BEC campaign abusing SharePoint 

ID: 1eee4e0d-3f6b-5637-882c-b81ddd12c8e7

STIX ID: report--1eee4e0d-3f6b-5637-882c-b81ddd12c8e7

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender analysts report a sophisticated AiTM phishing and BEC campaign against the energy sector in which attackers abused trusted SharePoint links to harvest session cookies, created inbox rules to hide activity and persist, and conducted a large internal and external phishing campaign (600+ emails) that led to multiple account compromises; the report provides detections, remediation steps (including revoking session cookies and removing malicious inbox rules), recommended protections (MFA, conditional access, continuous access evaluation), and two attacker IP IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.