A Fake Voicemail Is All It Takes: New AiTM Campaign Bypasses MFA Across US, Canadian, and European Firms

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Campaign identified: A widespread adversary-in-the-middle (AiTM) phishing campaign is compromising Microsoft 365 accounts.
  • Cluster overlap: The activity shares significant technical and behavioral overlap with the "Payroll Pirates" cluster Microsoft tracks as Storm-2755.
  • Broad reach: Targets span healthcare, education, manufacturing, government, and professional services across the United States, Canada, and Europe.

An ongoing email-driven adversary-in-the-middle (AiTM) phishing campaign compromises Microsoft 365 accounts to collect finance-related email, with hundreds of organizations targeted in July 2026 alone, with confirmed intrusions across a broad range of environments.

Arctic Wolf Labs has disclosed the operation uses voicemail-themed phishing emails carrying Microsoft branding and fabricated caller ID, date, duration, and reference number details designed to manufacture urgency. 

Voicemail Lures and AiTM Proxies Bypass MFA

Emails follow a consistent subject-line format: "[Organization] :ATTN: Review messages. Ref id: [random string]." Clicking the "OPEN [Organization] VOICEMAIL PORTAL" button starts a multi-stage redirect chain abusing Google Meet, Google Ads infrastructure, and AWS S3 buckets before reaching an AiTM proxy, the report said

Redacted phishing email showing the voicemail notification lure | Source: Arctic Wolf Labs
Redacted phishing email showing the voicemail notification lure | Source: Arctic Wolf Labs

That proxy relays the Microsoft OAuth authentication flow in real time, matching the legitimate sign-in page's source code, and intercepts the resulting session material even when multi-factor authentication (MFA) is enabled.

The official Microsoft 365 login page is proxied through an AiTM-generated page | Source: Arctic Wolf Labs
The official Microsoft 365 login page is proxied through an AiTM-generated page | Source: Arctic Wolf Labs

Residential Proxies and Eight-Hour Session Maintenance

Before reaching that proxy, victims are silently fingerprinted, as hidden JavaScript collects:

A separate lookup stores the victim's country code in a cookie – likely so later, automated sign-ins can be routed through proxy infrastructure matching the victim's real location. 

Multi-stage redirect chain using Google Meet, Google Ads, and AWS S3 infrastructure to route victims to an AiTM phishing proxy | Source: Arctic Wolf Labs
Multi-stage redirect chain using Google Meet, Google Ads, and AWS S3 infrastructure to route victims to an AiTM phishing proxy | Source: Arctic Wolf Labs

Once access is established, malicious sign-ins originate from rotating residential proxy addresses, most commonly identified as anyIP. 

Typically 11 to 24 hours after initial access, automated activity refreshes each compromised session at approximately eight-hour intervals, retaining the same SessionID while source IP, ASN, and geographic location change.

Graph Reconnaissance and Mailbox Collection

Consistent with Storm-2755, the actor uses Microsoft Graph to enumerate payroll, HR, finance, and administrative personnel, then accesses messages on payroll, invoices, banking, and benefits, targeting healthcare, education, manufacturing, government, and professional services across the U.S., Canada, and Europe.

A high-fidelity indicator is the MailItemsAccessed using a combination of Client App ID and API ID that Arctic Wolf found in no legitimate Outlook activity anywhere in its telemetry. 

Users who identify a compromise associated with this campaign should:

In other recent news, malware can now hijack Google Passkeys without asking for a fingerprint. A July report observed a hospitality Wi-Fi campaign leveraging gateway-level DNS poisoning against Microsoft authentication domains and AITM account compromise. 

A 2025 Gmail voicemail phishing scam used malicious CAPTCHA on fake websites to steal user credentials.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: