Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign

Microsoft Defender researchers have identified a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting organizations within the energy sector through the exploitation of SharePoint file-sharing systems. This multi-stage attack resulted…

Microsoft Defender researchers have identified a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting organizations within the energy sector through the exploitation of SharePoint file-sharing systems. This multi-stage attack resulted in the compromise of multiple user accounts, leading to extensive business email compromise (BEC) operations.

Initial Compromise Through Trusted Vendor

The attack commenced with phishing emails originating from a compromised vendor's email address. The attackers used SharePoint URLs that required authentication, imitating legitimate document-sharing processes to bypass suspicion. By exploiting the trust in Microsoft SharePoint and OneDrive services, which are prevalent in enterprise environments, the attackers avoided traditional email security filters.

Victims who accessed the malicious links and provided credentials on mock login pages unwittingly gave attackers access to their user sessions. Subsequently, the attackers created inbox rules to delete incoming emails and mark messages as read, thereby maintaining stealth and preventing the detection of suspicious activities.

Following the initial compromise, attackers launched a significant phishing campaign, distributing over 600 emails to both internal and external contacts of the victim organization. This campaign targeted recipients identified from recent email threads, expanding the attack's reach.

Attackers actively monitored compromised mailboxes, deleting undelivered and out-of-office notifications to remain undetected. In cases where recipients questioned the legitimacy of emails, attackers responded from compromised accounts to falsely confirm authenticity before erasing the conversation threads, thus maintaining persistence without alerting victims.

This multi-stage attack resulted in the compromise of multiple user accounts, leading to extensive business email compromise (BEC) operations.
Peter Collins · Thehackingpost

Microsoft Defender Experts identified additional compromised users by analyzing landing IP and sign-in patterns, revealing the campaign's extensive impact across multiple organizations in the energy sector.

Microsoft emphasizes the insufficiency of password resets alone for mitigating AiTM attacks. Organizations must also revoke active session cookies, remove attacker-created inbox rules, and reset any modified multi-factor authentication (MFA) settings. Attackers can sustain access through stolen session cookies and may register alternative MFA methods using attacker-controlled phone numbers.

Microsoft advises the implementation of conditional access policies that assess sign-in requests using identity signals such as IP location, device status, and user group membership. Additional security layers can be ensured by continuous access evaluation, security defaults in Azure Active Directory, and advanced anti-phishing solutions.

To detect suspicious activities, including multiple account sign-in attempts and malicious inbox rule creation, the deployment of Microsoft Defender XDR is recommended.

Advertisement

178.130.46.8 (Attacker infrastructure) 193.36.221.10 (Attacker infrastructure)

Organizations within the energy sector should immediately search for these IP addresses in authentication logs and investigate any related sign-in activities.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories