AI-Crafted M365 Sign-In Lure for AitM Session Hijacking (Arctic Wolf Storm-2755 Wave)
On August 7, 2026, Arctic Wolf Labs flagged a "widespread" adversary-in-the-middle (AitM) phishing campaign that hijacks Microsoft 365 accounts to identify personnel involved in financial workflows and harvest related email. Voicemail-themed lures run through a six-stage redirection chain abusing Google Meet, Google Ads and Amazon S3 to bypass reputation filters; credentials and MFA codes are captured on AitM proxy pages, with residential proxies disguising sign-ins and automated activity keeping compromised sessions alive at roughly 8-hour intervals. Arctic Wolf observed hundreds of organizations targeted last month across healthcare, education, manufacturing, government and professional services in the US, Canada and Europe, with tactical overlaps to Microsoft's Payroll Pirate (Storm-2755) cluster. This demo ships an AI-crafted phishing lure in the same shape as those M365 sign-in lures: an account-verification document ("unusual sign-in activity — verify your identity within 24 hours") whose button leads to a credential-harvesting AitM proxy page (placeholder URL, safe to open anywhere). The clean twin is the sanitized version. OPSWAT AI Content Inspector analyzes document intent — urgency cues, sign-in pressure, deceptive call-to-action — and flags the lure before it reaches finance staff mailboxes, the same treatment that neutralizes Arctic Wolf's M365 AitM wave.
Attack Technique
Adversary-in-the-Middle (AitM) spearphishing link via multi-stage redirect chain (T1566.002)
MITRE ATT&CK
T1566.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗