01A trusted-looking lure reaches the user
The January campaign used a trusted compromised sender and SharePoint workflow, while the April campaign used code-of-conduct PDF lures. Tycoon2FA supported broad brand impersonation.
Useful logs: Email
Threat report
Microsoft's 2026 reporting shows AiTM phishing using trusted collaboration lures, session theft, cloud-account reuse, mailbox concealment, and follow-on phishing.
Reported facts and defensive takeaways are labeled separately.
Public reporting
Adversary-in-the-middle phishing remained a significant cloud-identity threat in 2026 because attackers could proxy legitimate authentication, capture authenticated session material, and operate as the victim even after MFA succeeded. Microsoft's January SharePoint/BEC reporting, March Tycoon2FA analysis, and April code-of-conduct campaign describe distinct operations that share this session-theft problem without forming one universal campaign.
MFA success does not automatically make the resulting session trustworthy. A stolen authenticated session can survive a password-only response, trusted collaboration or compromised sender identities can improve lure credibility, and a compromised mailbox can become a new phishing distribution point. Defenders therefore need correlation across email, click, identity, session, and cloud-audit telemetry.
Public reporting
01The January campaign used a trusted compromised sender and SharePoint workflow, while the April campaign used code-of-conduct PDF lures. Tycoon2FA supported broad brand impersonation.
Useful logs: Email
02Redirects, staging pages, CAPTCHA, and legitimate collaboration or authentication surfaces can make the transition appear familiar while moving the user toward attacker-controlled AiTM infrastructure.
Useful logs: Network, Email
03The attacker sits between the user and legitimate authentication, capturing credentials, MFA interaction, and authenticated session material rather than simply presenting a static fake login page.
Useful logs: Authentication, Network
04The attacker operates as the compromised cloud identity. In the January campaign, Microsoft observed attacker access from another IP after the phishing sequence.
Useful logs: Authentication, Identity
05The January campaign created an Inbox rule that deleted incoming messages and marked them as read. Tycoon2FA reporting also describes possible post-compromise authenticator and mailbox-rule changes.
Useful logs: Saas Audit, Identity
06The January campaign selected recipients from recent threads, contacts, internal and external users, and distribution lists, then managed NDR, out-of-office, and authenticity-question messages.
Useful logs: Email, Saas Audit
07Microsoft reported more than 600 phishing messages from one compromised identity and additional recipients entering new AiTM flows.
Useful logs: Email, Network, Authentication
Defensive takeaways
AiTM delivery can inherit trust from compromised organizations or familiar collaboration workflows.
Useful logs: Email
The correlation connects the user action to possible replay of an authenticated session without treating IP change alone as malicious.
Useful logs: Network, Authentication, Identity
AiTM can steal authenticated session material after MFA completes, so the success event does not close the investigation.
Useful logs: Authentication, Saas Audit
Mailbox concealment can hide warnings, replies, and delivery notifications while an attacker operates the account.
Useful logs: Saas Audit
Trusted compromised accounts can become the delivery mechanism for the next AiTM wave.
Useful logs: Email
Shared source infrastructure can expose the blast radius when combined with user, time, application, and risk context.
Useful logs: Authentication, Threat Intelligence
Active mailbox management shows post-compromise intent and can distinguish BEC activity from a benign sign-in anomaly.
Useful logs: Email, Saas Audit
Mail telemetry connects trusted-sender delivery, campaign recipients, follow-on phishing, and mailbox-derived targeting.
URL-click and redirect-chain telemetry connects the delivered message to the user's actual navigation path.
Sign-in telemetry exposes the post-click source, browser, risk, device-trust, and session context needed to assess replay.
Cloud and Exchange audit logs show whether the suspicious session progressed into mailbox control or other account changes.
Identity context helps distinguish a one-off network transition from a compromised authenticated session.
Defensive takeaways
Correlate an email-origin URL click with same-user successful browser authentication inside a short window, then require multiple source, phishing, identity-risk, or device-trust signals.
Add confidence when suspicious session use is followed by Inbox-rule changes, message concealment, unusual sending, or other cloud operations.
Defensive takeaways
Start from a bounded campaign message or recipient set, recover Safe Links clicks, and review successful browser sign-ins with source, risk, device, and session context.
Review mailbox rules and outbound mail from confirmed identities, then feed every new recipient back into click and sign-in scoping.
Public reporting
2 values178[[.]]130[[.]]46[[.]]8193[[.]]36[[.]]221[[.]]101 valuesNEW PROPOSAL – NDA2 valuesacceptable-use-policy-calendly[[.]]decompliance-protectionoutlook[[.]]de3 valuescocinternal[[.]]comgadellinet[[.]]comharteprn[[.]]com5 valuescocpostmaster[@]cocinternal[.]comnationaladmin[@]gadellinet[.]comnationalintegrity[@]harteprn[.]comm365premiumcommunications[@]cocinternal[.]comdocumentviewer[@]na[.]businesshellosign[.]de3 valuesAwareness Case Log File – Monday 13th, April 2026.pdfAwareness Case Log File – Tuesday 14th, April 2026.pdfAwareness Case Log File – Wednesday 15th, April 2026.pdf3 values5DB1ECBBB2C90C51D81BDA138D4300B90EA5EB2885CCE1BD921D692214AECBC6B5A3346082AC566B4494E6175F1CD9873B64ABE6C902DB49BD4E8088876C9EAD11420D6D693BF8B19195E6B98FEDD03B9BCBC770B6988BC64CB788BFABE1A49DReview record
The approved source set covers Microsoft's January SharePoint/BEC campaign, March Tycoon2FA analysis, and an April 14–16 code-of-conduct campaign published in May. It does not claim continuous activity or a single shared operator.
Three Microsoft investigations independently document AiTM phishing, authenticated session theft or token compromise, and cloud-account abuse in 2026. Confidence is bounded to the cited behavior; infrastructure, lures, post-compromise actions, and operators differ across the reports.
Microsoft's January reporting followed a trusted compromised sender into a SharePoint-style lure, an AiTM compromise, later cloud-account access from another IP, Inbox-rule concealment, and more than 600 follow-on phishing messages. The attacker also monitored delivery notifications and authenticity questions, and additional clickers entered new AiTM flows.
Microsoft described Tycoon2FA as an AiTM phishing-as-a-service platform operating at large scale. Its capabilities included brand impersonation, anti-bot screening, CAPTCHA, redirect chains, and interception of credentials, MFA flows, and authenticated session cookies. The important defensive point is the authenticated session: password reset alone does not necessarily invalidate stolen session material.
Microsoft's separate April 14–16 campaign used code-of-conduct and compliance-themed PDFs, attacker-controlled landing infrastructure, CAPTCHA and staging, then a proxied legitimate Microsoft authentication flow. Microsoft reported more than 35,000 targeted users across more than 13,000 organizations in 26 countries.
These reports share a behavior pattern, not one universal chain. The lures, infrastructure, scale, and post-compromise actions differ, so detection should focus on message → click → authentication → session context → cloud behavior rather than a permanent IOC list.
Supporting context
T1566.002 · Spearphishing LinkThe reported campaigns delivered phishing links through trusted or convincing email and collaboration workflows.
T1204.001 · Malicious LinkCompromise depended on a recipient following a malicious or attacker-controlled link path.
T1539 · Steal Web Session CookieAiTM infrastructure captured authenticated session material that could be replayed after MFA completed.
T1078.004 · Cloud AccountsThe attacker reused the compromised cloud identity to access Microsoft 365 resources.
T1114.002 · Remote Email CollectionThe source campaign used mailbox content and recent threads to select recipients and manage follow-on phishing.