Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions

Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions










Attackers are quietly turning trusted Microsoft Outlook mailboxes into launchpads for stealing multi factor authenticated Microsoft 365 sessions, even when users think they are protected.

Adversary in the middle phishing has evolved into a reliable tool for hijacking live cloud sessions that organizations depend on for daily work.

The activity surfaced in May 2026, when a single phishing email sent to a small group of employees triggered a wider security incident across multiple organizations.

Once the first accounts were compromised, the attackers reused those Outlook mailboxes to resend the same procurement themed lures deeper into the victim networks and out to external partners.

Analysts from Infoblox traced that email back to a larger campaign and began mapping out how the attackers were abusing Outlook to sit between users and their Microsoft 365 login pages.

Infoblox said in a report shared with Cyber Security News (CSN) that the campaign does not target random users.

It focuses on universities, enterprises, and multinational institutions, including bodies linked to the European Union and United Nations.

The lures mimic everyday business workflows such as requests for information, bid invitations, and shared project documents, which makes them hard for busy staff to ignore.

In many cases, the phishing emails arrive from familiar internal addresses, turning trusted communication channels into tools for compromise.

Redacted screenshot of sample phishing emails sent to targeted victims through compromised Microsoft Outlook accounts (Source - Infoblox)
Redacted screenshot of sample phishing emails sent to targeted victims through compromised Microsoft Outlook accounts (Source – Infoblox)

The original report shows redacted screenshots of these emails that were sent through compromised Microsoft Outlook accounts, highlighting realistic subject lines and urgent deadlines designed to rush decisions.

Once victims click, they enter a path of fake download pages, CAPTCHA prompts, and cloned login portals that carefully imitate Microsoft 365 and other services.

This flow feels normal to users while quietly steering them into attacker controlled infrastructure.

The broader impact of this campaign stretches beyond one organization or sector. Since attackers are harvesting session cookies and tokens, they inherit fully authenticated identities inside Microsoft 365 rather than simply stealing passwords.

That level of access supports downstream abuse such as payroll redirection, mailbox searches, and SaaS account takeovers similar to the Storm 2755 activity seen in other AiTM session hijacking attacks.

Hackers Abuse Compromised Outlook Accounts

At the core of this operation is adversary in the middle phishing that turns Outlook itself into a trusted relay for Microsoft 365 session theft.

After compromising an initial mailbox, attackers send professionally written procurement themed emails to both internal and external contacts, multiplying their reach with each new hijacked account.

When a recipient clicks the embedded link, they typically land on a fake document portal hosted on compromised domains such as testserveren[.]com or barifurniture[.]net.

These pages copy the look of file sharing platforms or procurement portals and present several “shared” files that appear relevant to the email.

Download attempts do not deliver documents; instead, they redirect victims through CAPTCHA steps and onward to spoofed Microsoft 365 login pages.

From the user’s perspective, they simply enter their email address, pass a CAPTCHA, and sign in to Microsoft 365 as usual.

Behind the scenes, reverse proxy based kits such as EvilProxy, FlowerStorm, and Kali365 relay the credentials to the real Microsoft service while capturing the live session cookies.

Screenshot of a fake download page impersonating ConstructConnect (Source - Infoblox)
Screenshot of a fake download page impersonating ConstructConnect (Source – Infoblox)

The attacker then reuses these cookies to open authenticated sessions, bypassing MFA and gaining full visibility into Outlook mailboxes, SharePoint files, and broader Microsoft 365 resources.

This same model has driven recent AiTM phishing attacks targeting Microsoft 365 and Google accounts across the industry.

Once inside the account, the attacker often continues the loop by sending new phishing emails from that compromised mailbox, extending the chain of trust abuse.

This mirrors other modern techniques like browser in the middle attacks, which also focus on stealing authenticated session states rather than raw credentials.

The result is a high speed intrusion path that aligns with recent campaigns where attackers deploy AiTM phishing pages to gain instant access to SaaS environments and business workflows.

Why MFA and domain checks are not enough

This campaign underlines a hard truth for defenders: multi factor authentication by itself cannot stop an attacker who already sits in the middle of the login process.

When authentication flows are proxied in real time, the attacker captures and replays the same session token that proves the user passed MFA, effectively inheriting their identity.

Similar patterns have appeared in other new AiTM attack campaigns that bypass MFA for Microsoft 365 and Okta users using HR themed lures and layered redirects.

Traditional detection based on domain reputation and URL filtering also struggles in this scenario. The actors prefer aged domains like testserveren[.]com and barifurniture[.]net that previously hosted legitimate content and show no recent registration spikes.

Many of their phishing pages are delivered through RDGA generated domains with corporate sounding names, aligned with trends in phishing as a service ecosystems such as Rockstar 2FA and newer kits documented in Microsoft’s guidance on defending against advancing AiTM attacks.

Infoblox recommends that organizations add DNS based visibility and threat intelligence on top of existing controls to spot these campaigns earlier in the kill chain.

RDGA patterns, subdomain naming conventions, and infrastructure reuse leave fingerprints that remain visible to passive DNS analysis even after individual phishing URLs are gone.

Coupling DNS telemetry with continuous monitoring of Microsoft 365 sign in behaviors and enforcing conditional access policies can help reduce the window in which stolen sessions remain useful to attackers, reinforcing lessons shared across multiple reports on AiTM phishing and session hijacking against Microsoft 365 environments.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain barifurniture[.]net Likely compromised, now hosting fake file download pages. 
Domain satoriestate[.]com Likely compromised, hosting fake document download content. 
Domain sohantraders[.]com Likely compromised, hosting fake document download content. 
Domain testserveren[.]com Dormant domain repurposed for UN and OpenGov themed fake downloads. 
Domain vresortsliving[.]com Likely compromised, hosting fake document download pages. 
Domain consistenthostinghub[.]de FlowerStorm / Storm 1167 phishing infrastructure domain. 
Domain designenhancessatisfaction[.]de FlowerStorm / Storm 1167 phishing infrastructure domain. 
Domain evergreenhostingoptions[.]de FlowerStorm / Storm 1167 phishing infrastructure domain. 
Domain innovativegrowthstrategy[.]de FlowerStorm / Storm 1167 phishing infrastructure domain. 
Domain reliablecontinuitysolutions[.]de FlowerStorm / Storm 1167 phishing infrastructure domain. 
Domain sustainablegrowthlaunch[.]de FlowerStorm / Storm 1167 phishing infrastructure domain. 
Domain solidhostingservices[.]de FlowerStorm / Storm 1167 phishing infrastructure domain. 
Domain usersatisfactionlab[.]de FlowerStorm / Storm 1167 phishing infrastructure domain. 
Domain assessmentevaluationreport[.]com EvilProxy phishing as a service infrastructure domain. 
Domain corporatetermscompliance[.]com EvilProxy phishing as a service infrastructure domain. 
Domain employeehandbookcompliance[.]com EvilProxy phishing as a service infrastructure domain. 
Domain esignidentification[.]com EvilProxy phishing as a service infrastructure domain. 
Domain q1evaluationperformance[.]net EvilProxy phishing as a service infrastructure domain. 
Domain duemineral[.]uk Kali365 phishing as a service infrastructure domain. 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposuremalware to businesses an

The post Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions appeared first on Cyber Security News.






Tushar Subhra Dutta





Go to cyber-security-news





Posted

in

, ,

by