logo

Credential Harvesting Against Cloud Email Accounts Using Adversary-in-the-Middle Toolkit

ID: 238f5ce3-daa0-4987-846b-0aba9ce62223

STIX ID: report--238f5ce3-daa0-4987-846b-0aba9ce62223

Threat Score

72/100

Uploaded: 2026-04-13

Created by: Report Uploader

TLP:GREEN
...
...
Between 8 and 12 April 2026, investigators observed a credential-harvesting phishing campaign targeting legal-sector cloud email users. Attackers used a spoofed Microsoft 365 login hosted at https://sharepoint-docs-verify.com/client-review, operated as an adversary-in-the-middle to capture credentials and session cookies, and later abused compromised accounts for internal phishing and mailbox forwarding—suggesting objectives of business email compromise, internal reconnaissance, and long-term mailbox access.