What is Happening Right Now
An active, widespread email-driven phishing campaign is employing adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts, with the specific aim of identifying key personnel involved in financial workflows and gathering sensitive email data. This is not a theoretical threat. It is happening right now, at scale, across industries including healthcare, manufacturing, government, and professional services.
There is also a data extortion group known as UNC6671 that has been conducting voice phishing, or "vishing", attacks against enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. These calls are designed to trick victims into visiting spoofed login portals where AitM infrastructure intercepts their credentials and multi-factor authentication (MFA) tokens in real time.
Taken together, these campaigns represent a fundamental shift in how attackers are targeting organizations and why every business leader and employee needs to understand it.
What is an Adversary-in-the-Middle (AitM) Attack?
Most people have heard of phishing. You click a bad link, enter your password on a fake website, and attackers steal it. AitM attacks are different and far more dangerous.
In an AitM phishing attack, an attacker positions a server between the victim and a legitimate login page. This proxy relays the victim's credentials to the real service in real time, completes the authentication flow – which includes any MFA challenge – and captures the resulting session cookie or token. The attacker then replays that token to access the victim's account without needing the password or MFA device again.
In plain language: the attacker is not stealing your password. They are stealing proof that you already successfully logged in.
Unlike traditional credential phishing, AitM attacks steal the authenticated session itself. This is what makes them effective against time-based one-time password (TOTP), push-based MFA, and SMS codes.
This means that while still critically important, turning on MFA is no longer sufficient protection on its own against this class of attack.
How These Attacks Are Carried Out
Here is what a typical AitM attack looks like in practice:
Attack chains involve the use of voicemail-themed phishing emails that lead victims to AitM decoy pages acting as a proxy for the legitimate Microsoft account authentication flow, while stealthily capturing credentials and MFA codes.
In the vishing variant used by threat group UNC6671, the attack begins with a phone call:
Callers contact targeted employees on their personal cell phones, posing as internal IT or help desk personnel, citing a mandatory migration to passkeys or a required MFA update.
Once inside, the attackers move fast. Upon establishing persistence, attackers transition from interactive browser-based reconnaissance to automated exfiltration, using scripts to harvest high-value data from email, SharePoint, and OneDrive repositories.
There is also a third dimension to this threat. Researchers have demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device they control, obtain a Primary Refresh Token (PRT), and add further authentication methods. Administrator privileges are not required to carry this out.
Why This Attack is Becoming So Common
There are several reasons AitM phishing has exploded in adoption among cybercriminals. First, the tools are widely available. Proxy-based attacks are frequently packaged as turnkey phishing kits, making AitM capabilities accessible to operators with minimal technical skills. A threat actor does not need to be technically sophisticated to launch one of these campaigns.
Second, businesses have gotten better at traditional defenses. Phishing campaigns continue to improve in sophistication, blending social engineering, delivery infrastructure, and authentication abuse to remain effective against evolving security controls. As organizations have adopted MFA more broadly, attackers have adapted by targeting what comes after a successful login – the session token – rather than the login itself.
Third, the financial incentive is enormous. As reported by The Hacker News, between January 7 and May 12, 2026, over $10.6 million in Bitcoin payments were tracked to wallets associated with UNC6671 alone. Initial ransom demands reach north of $3 million, and in more than 53% of tracked cases, threat actors settled for an average of $750,000.
The combination of low barriers to entry and high financial reward has made this one of the fastest-growing attack techniques in the cybersecurity landscape.
What Our Security Tech Stack Is Doing to Stay Ahead
Protecting our clients against AitM attacks requires multiple layers of defense working together. Here's what we have in place:
Together, these tools help our team detect and respond to AitM activity that gets past a user's initial login – the point at which most organizations have no visibility at all.
What You Need to Be Telling Your Employees
Technology controls are essential, but your employees remain the most important line of defense against this type of attack. Here is what your team needs to know:
Spot the signs of a vishing attack:
Watch the URL, always:
Understand that MFA is not infallible:
Reporting is the most important action:
A Final Word
The threat of AitM phishing and token theft is real, it is active, and it is specifically targeting the tools your business runs on every day – including Microsoft 365. The good news is that with the right combination of technology, process, and user awareness, these attacks can be detected and stopped.
Our team is monitoring for these threats around the clock on your behalf. But your employees are a critical part of this defense. Invest in their awareness. Teach them to slow down, verify, and report. It may be the single most impactful action your organization takes this year.
If you have questions about how we protect environments, or would like to discuss implementing phishing-resistant MFA or security awareness training for your team, please reach out! We are here to help.
- Kent Goodrow, Chief Information Security Officer
kgoodrow@systemsengineering.com