Resurgence of a multi‑stage AiTM phishing and BEC campaign abusing SharePoint
ID: 1eee4e0d-3f6b-5637-882c-b81ddd12c8e7
STIX ID: report--1eee4e0d-3f6b-5637-882c-b81ddd12c8e7
Feed Name: Microsoft Security
Date Published: 2026-01-22
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
Microsoft Defender analysts report a sophisticated AiTM phishing and BEC campaign against the energy sector in which attackers abused trusted SharePoint links to harvest session cookies, created inbox rules to hide activity and persist, and conducted a large internal and external phishing campaign (600+ emails) that led to multiple account compromises; the report provides detections, remediation steps (including revoking session cookies and removing malicious inbox rules), recommended protections (MFA, conditional access, continuous access evaluation), and two attacker IP IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
