A Fake Voicemail Is All It Takes: New AiTM Campaign Bypasses MFA Across US, Canadian, and European Firms
- Campaign identified: A widespread adversary-in-the-middle (AiTM) phishing campaign is compromising Microsoft 365 accounts.
- Cluster overlap: The activity shares significant technical and behavioral overlap with the "Payroll Pirates" cluster Microsoft tracks as Storm-2755.
- Broad reach: Targets span healthcare, education, manufacturing, government, and professional services across the United States, Canada, and Europe.
An ongoing email-driven adversary-in-the-middle (AiTM) phishing campaign compromises Microsoft 365 accounts to collect finance-related email, with hundreds of organizations targeted in July 2026 alone, with confirmed intrusions across a broad range of environments.
Arctic Wolf Labs has disclosed the operation uses voicemail-themed phishing emails carrying Microsoft branding and fabricated caller ID, date, duration, and reference number details designed to manufacture urgency.
Voicemail Lures and AiTM Proxies Bypass MFA
Emails follow a consistent subject-line format: "[Organization] :ATTN: Review messages. Ref id: [random string]." Clicking the "OPEN [Organization] VOICEMAIL PORTAL" button starts a multi-stage redirect chain abusing Google Meet, Google Ads infrastructure, and AWS S3 buckets before reaching an AiTM proxy, the report said.
That proxy relays the Microsoft OAuth authentication flow in real time, matching the legitimate sign-in page's source code, and intercepts the resulting session material even when multi-factor authentication (MFA) is enabled.
Residential Proxies and Eight-Hour Session Maintenance
Before reaching that proxy, victims are silently fingerprinted, as hidden JavaScript collects:
- browser and operating-system details,
- screen dimensions,
- language and time-zone settings,
- WebGL data,
A separate lookup stores the victim's country code in a cookie – likely so later, automated sign-ins can be routed through proxy infrastructure matching the victim's real location.
Once access is established, malicious sign-ins originate from rotating residential proxy addresses, most commonly identified as anyIP.
Typically 11 to 24 hours after initial access, automated activity refreshes each compromised session at approximately eight-hour intervals, retaining the same SessionID while source IP, ASN, and geographic location change.
Graph Reconnaissance and Mailbox Collection
Consistent with Storm-2755, the actor uses Microsoft Graph to enumerate payroll, HR, finance, and administrative personnel, then accesses messages on payroll, invoices, banking, and benefits, targeting healthcare, education, manufacturing, government, and professional services across the U.S., Canada, and Europe.
A high-fidelity indicator is the MailItemsAccessed using a combination of Client App ID and API ID that Arctic Wolf found in no legitimate Outlook activity anywhere in its telemetry.
Users who identify a compromise associated with this campaign should:
- Revoke all active sessions for the affected account(s).
- Rotate credentials and re-register MFA for the affected user(s).
- Audit payroll and HR platform activity (e.g., Workday, ADP) for the full suspected dwell period.
- Review MailItemsAccessed audit logs for the unique API ID pairing described above to scope what data was accessed.
- Hunt for the eight-hour session-maintenance pattern across other accounts in the environment to identify additional compromises.
In other recent news, malware can now hijack Google Passkeys without asking for a fingerprint. A July report observed a hospitality Wi-Fi campaign leveraging gateway-level DNS poisoning against Microsoft authentication domains and AITM account compromise.
A 2025 Gmail voicemail phishing scam used malicious CAPTCHA on fake websites to steal user credentials.








