Cybercriminals bypassed Microsoft 365 multi-factor authentication (MFA) through an Adversary-in-the-Middle (AiTM) phishing attack, hijacked a finance employee’s active session, and used mailbox access to divert vendor payments to attacker-controlled bank accounts.
The campaign was fully cloud-based, leaving no malware or endpoint compromise behind. The attack began with a targeted HR-themed email claiming that the recipient’s paid-time-off request had been denied.
The message included a “View PTO Conflicting Dates” button hidden behind a SendGrid tracking link. After the finance user clicked, the link passed through several redirects before opening a fake Microsoft 365 sign-in page.
The AiTM phishing infrastructure acted as a relay between the victim and the legitimate Microsoft service. It captured the password and, more importantly, the authenticated session cookie after the user approved the MFA prompt.
Microsoft 365 MFA Bypass
This allowed the attackers to replay the valid Microsoft 365 session from commercial VPN infrastructure. Because MFA had already been satisfied in the stolen token, the attacker did not need to trigger a new MFA request or guess credentials.
Sign-in records showed single-factor authentication with MFA marked as “previously satisfied,” a key indicator of session-token replay.
The threat actor used the hijacked session to access Exchange Online, SharePoint, Microsoft 365 Search, and a shared accounts-payable mailbox available through the victim’s existing permissions.
They created three malicious inbox rules designed to archive and mark payment-related emails as read, then stop further rule processing.
These rules hid genuine vendor collection messages and internal correspondence that could have exposed the fraud. The criminals then ran a two-part vendor payment-diversion operation:
- First, they impersonated a vendor from a free-webmail account and requested that payments be changed from checks to ACH transfers.
- They supplied fraudulent ACH authorization forms and W-9 documents containing attacker-controlled banking details.
- Later, they impersonated an internal senior accounts-payable employee from a look-alike domain, sending additional bank-update requests to make the fraudulent change appear legitimate.
The operation continued for roughly 30 days, with the most active payment-diversion emails occurring between Days 2 and 24. The attackers continued to access the victim’s Microsoft 365 environment after the fraud messages ended.
The incident was discovered through identity and mailbox telemetry rather than endpoint detection.
Investigators identified an atypical-travel alert showing the same Microsoft 365 session active from Amsterdam and Los Angeles within about one minute an impossible travel pattern consistent with VPN-backed session replay.
The activity maps to several MITRE ATT&CK techniques, including spearphishing links, web-session-cookie theft, valid cloud accounts, email-hiding rules, remote email collection, SharePoint data access, and financial theft, trendaisecurity said.
Organizations should enable Microsoft Entra token protection, investigate suspicious inbox-rule changes, and require out-of-band verification such as a call to a known vendor phone number for every banking-detail update.
These controls can disrupt payment-diversion BEC even after a mailbox session is compromised.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN
