SOCLIFE
SOCLIFE

Evidence-led security analysis

Published knowledge

Search SOC//LIFE

ThreatsTHREAT-003

Threat report

AiTM Phishing in 2026: Session Theft Beyond MFA

Microsoft's 2026 reporting shows AiTM phishing using trusted collaboration lures, session theft, cloud-account reuse, mailbox concealment, and follow-on phishing.

Public research

Reported facts and defensive takeaways are labeled separately.

Reviewed

Public reporting

What happened

Adversary-in-the-middle phishing remained a significant cloud-identity threat in 2026 because attackers could proxy legitimate authentication, capture authenticated session material, and operate as the victim even after MFA succeeded. Microsoft's January SharePoint/BEC reporting, March Tycoon2FA analysis, and April code-of-conduct campaign describe distinct operations that share this session-theft problem without forming one universal campaign.

Why SOC teams should care

MFA success does not automatically make the resulting session trustworthy. A stolen authenticated session can survive a password-only response, trusted collaboration or compromised sender identities can improve lure credibility, and a compromised mailbox can become a new phishing distribution point. Defenders therefore need correlation across email, click, identity, session, and cloud-audit telemetry.

Public reporting

How the attack worked

  1. Initial Access01

    A trusted-looking lure reaches the user

    The January campaign used a trusted compromised sender and SharePoint workflow, while the April campaign used code-of-conduct PDF lures. Tycoon2FA supported broad brand impersonation.

    Useful logs: Email

  2. Initial Access02

    The user follows the phishing link path

    Redirects, staging pages, CAPTCHA, and legitimate collaboration or authentication surfaces can make the transition appear familiar while moving the user toward attacker-controlled AiTM infrastructure.

    Useful logs: Network, Email

Defensive takeaways

Behavior to watch

Logs that help

Email

Mail telemetry connects trusted-sender delivery, campaign recipients, follow-on phishing, and mailbox-derived targeting.

  • Unexpected SharePoint, document-sharing, or compliance lures from trusted or known senders.
  • Sudden campaign-like outbound or intra-organization sending from a compromised identity.
  • NDR, out-of-office, and authenticity-question handling around the compromise.

Network

URL-click and redirect-chain telemetry connects the delivered message to the user's actual navigation path.

  • Email-origin clicks into unfamiliar or source-reported infrastructure.
  • Redirect chains or click sources that align with suspicious authentication.

Authentication

Sign-in telemetry exposes the post-click source, browser, risk, device-trust, and session context needed to assess replay.

  • Successful browser sign-in after a phishing click from materially different context.
  • Medium/high risk, at-risk state, unmanaged/non-compliant device posture, or shared suspicious source infrastructure.

Saas Audit

Cloud and Exchange audit logs show whether the suspicious session progressed into mailbox control or other account changes.

  • New or modified Inbox rules after suspicious authentication.
  • Unexpected mailbox operations, sending, or account changes from the suspicious identity/source.

Identity

Identity context helps distinguish a one-off network transition from a compromised authenticated session.

  • Unexpected authenticator changes or session behavior after suspected AiTM.
  • The same suspicious source appearing across multiple cloud identities.

Defensive takeaways

How to detect this behavior

Correlate phishing clicks with suspicious cloud sessions

Correlate an email-origin URL click with same-user successful browser authentication inside a short window, then require multiple source, phishing, identity-risk, or device-trust signals.

Logs needed

  • Safe Links click telemetry with user, URL, message ID, source, action, redirect chain, and verdict.
  • Entra sign-ins with user, source, browser, device trust, risk, session, application, and timestamp.

Raise confidence with post-authentication mailbox behavior

Add confidence when suspicious session use is followed by Inbox-rule changes, message concealment, unusual sending, or other cloud operations.

Logs needed

  • Exchange Online / Microsoft 365 audit activity with identity, action, source, object, and parameters.
  • Message telemetry for sender, recipient, direction, subject, and timestamps.
View detection

Defensive takeaways

How to hunt this behavior

Trace message → click → post-click session

Start from a bounded campaign message or recipient set, recover Safe Links clicks, and review successful browser sign-ins with source, risk, device, and session context.

What would weaken it

  • No relevant recipients clicked the source campaign messages.
  • Post-click sessions resolve to expected network and device context with no independent risk or cloud-activity signal.

Follow compromised senders into the next exposure population

Review mailbox rules and outbound mail from confirmed identities, then feed every new recipient back into click and sign-in scoping.

What would weaken it

  • Sending volume and recipient selection match the user's established business workflow.
  • Mailbox-rule or message-management changes have an approved owner and predate the suspicious session.
View threat hunt

Public reporting

Indicators reported by the source

Values are defanged and are not live links.
Sign-in infrastructure reported by Microsoft in the January 2026 SharePoint AiTM/BEC campaign.2 values
  • Ip178[[.]]130[[.]]46[[.]]8
  • Ip193[[.]]36[[.]]221[[.]]10
Subject value published by Microsoft for hunting the January 2026 campaign.1 values
  • OtherNEW PROPOSAL – NDA
Attacker-controlled landing domain reported for the April 2026 code-of-conduct AiTM campaign.2 values
  • Domainacceptable-use-policy-calendly[[.]]de
  • Domaincompliance-protectionoutlook[[.]]de
Sender domain reported for the April 2026 code-of-conduct AiTM campaign.3 values
  • Domaincocinternal[[.]]com
  • Domaingadellinet[[.]]com
  • Domainharteprn[[.]]com
Sender address reported for the April 2026 code-of-conduct AiTM campaign.5 values
  • Othercocpostmaster[@]cocinternal[.]com
  • Othernationaladmin[@]gadellinet[.]com
  • Othernationalintegrity[@]harteprn[.]com
  • Otherm365premiumcommunications[@]cocinternal[.]com
  • Otherdocumentviewer[@]na[.]businesshellosign[.]de
PDF filename reported in the April 2026 code-of-conduct campaign.3 values
  • FilenameAwareness Case Log File – Monday 13th, April 2026.pdf
  • FilenameAwareness Case Log File – Tuesday 14th, April 2026.pdf
  • FilenameAwareness Case Log File – Wednesday 15th, April 2026.pdf
SHA-256 reported for a code-of-conduct campaign PDF.3 values
  • Hash5DB1ECBBB2C90C51D81BDA138D4300B90EA5EB2885CCE1BD921D692214AECBC6
  • HashB5A3346082AC566B4494E6175F1CD9873B64ABE6C902DB49BD4E8088876C9EAD
  • Hash11420D6D693BF8B19195E6B98FEDD03B9BCBC770B6988BC64CB788BFABE1A49D

Review record

Sources and limitations

Reviewed
Reported window
January 2026 April 2026

Observation basis

The approved source set covers Microsoft's January SharePoint/BEC campaign, March Tycoon2FA analysis, and an April 14–16 code-of-conduct campaign published in May. It does not claim continuous activity or a single shared operator.

Confidence in this conclusion

Three Microsoft investigations independently document AiTM phishing, authenticated session theft or token compromise, and cloud-account abuse in 2026. Confidence is bounded to the cited behavior; infrastructure, lures, post-compromise actions, and operators differ across the reports.

Limitations

  • AiTM is a technique used across different activity sets and is not attributed here to one actor.
  • The January SharePoint/BEC campaign, Tycoon2FA activity, and April code-of-conduct campaign are separate source contexts and must not be merged into one fictional intrusion chain.
  • Not every AiTM campaign uses CAPTCHA, mailbox rules, the same brands, or the same infrastructure.
  • The indicator set is source-scoped and historical; absence of those values does not rule out session theft.

January — trusted SharePoint workflow becomes BEC

Microsoft's January reporting followed a trusted compromised sender into a SharePoint-style lure, an AiTM compromise, later cloud-account access from another IP, Inbox-rule concealment, and more than 600 follow-on phishing messages. The attacker also monitored delivery notifications and authenticity questions, and additional clickers entered new AiTM flows.

March — Tycoon2FA industrializes the session-theft problem

Microsoft described Tycoon2FA as an AiTM phishing-as-a-service platform operating at large scale. Its capabilities included brand impersonation, anti-bot screening, CAPTCHA, redirect chains, and interception of credentials, MFA flows, and authenticated session cookies. The important defensive point is the authenticated session: password reset alone does not necessarily invalidate stolen session material.

April — code-of-conduct lures lead to AiTM token compromise

Microsoft's separate April 14–16 campaign used code-of-conduct and compliance-themed PDFs, attacker-controlled landing infrastructure, CAPTCHA and staging, then a proxied legitimate Microsoft authentication flow. Microsoft reported more than 35,000 targeted users across more than 13,000 organizations in 26 countries.

These reports share a behavior pattern, not one universal chain. The lures, infrastructure, scale, and post-compromise actions differ, so detection should focus on message → click → authentication → session context → cloud behavior rather than a permanent IOC list.

  1. Resurgence of a multi-stage AiTM phishing and BEC campaign abusing SharePoint

    Microsoft Security

  2. Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale

    Microsoft Security

  3. Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise

    Microsoft Security

Supporting context

ATT&CK mappings

Behavior comes first. These mappings do not imply attribution or complete coverage.