Hackers Use Procurement Phishing and AiTM Kits to Hijack MFA-Protected Microsoft 365 Sessions

A sophisticated phishing campaign is using procurement-themed emails and adversary-in-the-middle (AiTM) kits to steal MFA-protected Microsoft 365 sessions.

Rather than breaking MFA, attackers proxy legitimate sign-in flows and capture the session cookies and tokens created after victims authenticate.

The campaign reportedly targets enterprises, universities, multinational organizations, and public-sector entities through RFIs, bid invitations, and project-document lures.

Attackers send messages from previously compromised organizational mailboxes, making the email appear more credible and enabling further internal and external phishing distribution

Victims are routed through fake file-sharing pages impersonating services such as OpenGov, ConstructConnect, and United Nations-related platforms.

The pages may include personalized email-address paths, file-download prompts, CAPTCHA checks, and urgency-based language intended to make the workflow look legitimate.

Redacted screenshot of sample phishing emails sent to targeted victims through compromised Microsoft Outlook accounts (Source: infoblox)
Redacted screenshot of sample phishing emails sent to targeted victims through compromised Microsoft Outlook accounts (Source: infoblox)

Researchers observed malicious download portals on likely compromised, aged domains including testserveren[.]com, barifurniture[.]net, satoriestate[.]com, sohantraders[.]com, and vresortsliving[.]com.

The use of dormant domains instead of newly registered phishing sites can help attackers evade reputation-based blocking.

AiTM Kits Hijack Microsoft 365

After a victim passes the staged download and CAPTCHA process, the campaign presents a cloned Microsoft 365 sign-in page, sometimes branded for the targeted organization.

The AiTM server relays credentials and MFA interactions to the real Microsoft authentication service in real time, then intercepts the authenticated browser session.

The actor has been linked to multiple phishing-as-a-service tools, including EvilProxy, FlowerStorm/Storm-1167, and Kali365. EvilProxy uses reverse-proxy architecture to collect credentials, cookies, and authentication tokens.

At the same time, FlowerStorm is also designed to target Microsoft 365 users and bypass MFA through AiTM techniques.

Redacted screenshot of a fake authentication page impersonating the European Investment Bank (Source: infoblox)
Redacted screenshot of a fake authentication page impersonating the European Investment Bank (Source: infoblox)

Observed FlowerStorm-related domains follow recurring RDGA-style naming patterns, often combining corporate-sounding terms unde

Stolen session tokens can give an attacker authenticated access to a mailbox or cloud account without repeatedly requesting the victim’s password or MFA code. This access can support business email compromise, internal phishing, data theft, and lateral movement.

Organizations should treat unexpected procurement emails, document-sharing links, and CAPTCHA-gated sign-in prompts as high-risk especially when a login page appears after clicking an unsolicited document link.

Phishing-resistant authentication, conditional-access controls, session monitoring, DNS intelligence, and rapid token revocation can reduce exposure to these attacks. techcommunity, infoblox said.

Indicators of Compromise

Indicator TypeIOCDescription
Compromised hosting domainbarifurniture[.]netHosted fake NUS Consulting Group document-download content
Compromised hosting domainsatoriestate[.]comLikely compromised domain used for fake document portals
Compromised hosting domainsohantraders[.]comLikely compromised domain used for phishing delivery
Compromised hosting domaintestserveren[.]comHosted fake UN and OpenGov file-sharing pages

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories