SECURITY·중요도 8·2026. 08. 07.·The Hacker News

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

── KO ──────────────────

Microsoft 365를 겨냥한 AitM 피싱 공격에 대한 경고.

연구자들은 금융 관련 이메일을 수집하기 위해 Microsoft 365 계정을 탈취하는 광범위한 AitM 피싱 캠페인에 대해 경고했습니다. 이 캠페인은 주거용 프록시를 사용하여 악의적인 로그인 시도를 일반 소비자 트래픽으로 위장하고 있습니다. 이 공격은 핵심 인력의 이메일을 타겟으로 하여 재정 흐름에 관련된 정보를 수집하는 데 초점을 맞추고 있습니다.


── EN ──────────────────

Warning about AitM phishing attacks targeting Microsoft 365.

Researchers have alerted users to a widespread AitM phishing campaign aimed at hijacking Microsoft 365 accounts to collect emails related to financial workflows. The campaign uses residential proxies to disguise malicious logins as regular consumer traffic. This attack focuses on identifying key personnel and gathering sensitive information about finance.

원문 보기 →목록으로