Phishing campaigns continue to evolve by blending advanced social engineering with complex hosting infrastructure to bypass modern security controls.
According to a recent report from Microsoft Defender Research, a large scale credential theft campaign actively demonstrates this growing sophistication.
The operation utilizes code of conduct themed lures, a multi step attack chain, and legitimate email delivery services to distribute fully authenticated messages from attacker controlled domains.
Ultimately, the attack directs victims to a deceptive sign in experience that functions as an adversary in the middle phishing flow, enabling threat actors to proxy the session and steal authentication tokens in real time.
Sophisticated Lures and Evasion Tactics
Between April 14 and 16 of 2026, Microsoft Defender Research observed this massive campaign targeting over 35,000 users across 13,000 organizations.
The attacks heavily impacted the United States, with the healthcare and financial services sectors taking the brunt of the assault.
Emails masqueraded as internal compliance communications, bearing display names like Internal Regulatory COC and claiming a conduct policy review had been initiated.
To build trust, the messages utilized polished HTML templates and displayed fake green banners claiming the contents were securely encrypted via Paubox.

This screenshot illustrates the deceptive login prompts and intermediate staging pages utilized to capture user credentials during phishing attacks.
Each deceptive email included a PDF attachment containing fake disciplinary action logs. Security experts from Microsoft note that this CAPTCHA served as a gating mechanism to block automated analysis tools and sandbox environments.

Bypassing Authentication Controls
The final stage of the attack dynamically adjusted its behavior based on whether the victim used a mobile device or a desktop system.
Users were ultimately directed to a counterfeit Microsoft authentication page. Because this architecture relies on an adversary in the middle framework, the attackers intercept the traffic directly, effectively bypassing standard multi factor authentication defenses.

Microsoft emphasizes that traditional credential harvesting is no longer the sole threat, as capturing live session tokens provides immediate and unfettered account access.
To defend against these complex threats, organizations must deploy advanced anti phishing solutions and configure essential email security settings.
Microsoft Defender researchers recommend enabling Zero hour auto purge to quarantine malicious emails retroactively and using SmartScreen network protection to block access to deceptive domains.
Furthermore, security teams should prioritize the transition to passwordless authentication methods, such as Windows Hello or FIDO keys, to neutralize the risk of credential interception.
Indicators of Compromise
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.