Microsoft reported an adversary-in-the-middle (AiTM) phishing campaign targeting multiple energy-sector organizations by abusing Microsoft SharePoint file-sharing links to make lures appear legitimate and evade email-centric defenses. Initial emails—often sent from previously compromised, trusted accounts—used subject lines such as “NEW PROPOSAL – NDA” and directed recipients to a SharePoint URL that ultimately led to a fake login page designed to capture credentials and facilitate account takeover.
After victims authenticated, the attackers leveraged stolen credentials and intercepted authenticated session cookies to access mailboxes from different IP infrastructure (including 178.130.46.8 and 193.36.221.10). They then created inbox rules to delete incoming messages and mark emails as read, reducing the chance of detection while they launched follow-on phishing from the compromised accounts—sending hundreds of messages (including an instance of 600+ emails) to internal and external contacts and distribution lists based on recent email threads. The operators monitored responses, deleted out-of-office/undeliverable notices, and replied to legitimacy questions to sustain the campaign; Microsoft emphasized that password resets alone are insufficient, recommending revoking active session cookies, removing attacker-created inbox rules, and validating no unauthorized MFA changes were made.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage of Microsoft's findings included two attacker IP addresses for defenders to review in authentication logs. The reporting reinforced recommendations to hunt for suspicious sign-ins, session reuse, and attacker-created mailbox rules.
Microsoft published research describing the energy-sector AiTM and BEC campaign, warning that password resets alone are insufficient because stolen session cookies and attacker-made MFA changes can preserve access. The company advised defenders to revoke active sessions, remove malicious inbox rules, reverse unauthorized MFA changes, and strengthen protections with conditional access and phishing-resistant authentication.
Microsoft Defender XDR detected the activity across affected organizations, and Defender Experts took response actions including disrupting the AiTM activity and purging phishing emails. Microsoft also identified compromised users using sign-in and landing IP telemetry patterns.
After gaining access, the attackers created malicious inbox rules to delete or mark messages as read, monitored mailboxes, and used compromised accounts to send follow-on phishing to internal and external contacts. In at least one observed case, a single compromised account sent more than 600 phishing emails and the operators replied to skeptical recipients while deleting evidence to preserve credibility.
A multi-stage phishing campaign targeted multiple energy-sector organizations using SharePoint file-sharing lures sent from a trusted vendor or other previously compromised email account. Victims were redirected to an adversary-in-the-middle login page that captured credentials and authenticated session cookies, enabling account takeover and MFA bypass.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
8 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcego.theregister.com
Open sourcehelpnetsecurity.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.