Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
Incidents: Multi-stage phishing campaign uses AiTM tactics to bypass MFA and steal authentication tokens.
Deep Analysis and Expert Commentary
The campaign employs a multi-step attack chain, starting with highly credible emails that mimic internal communications. These emails direct victims through CAPTCHA and intermediate pages to filter out automated defenses, reinforcing legitimacy. The final stage involves an AiTM phishing flow, where attackers proxy authentication sessions in real time, capturing tokens even when MFA is enabled. This method is particularly dangerous as it bypasses traditional credential harvesting limitations. Mitigation requires layered defenses: user awareness training to recognize sophisticated lures, deployment of advanced email security solutions like Microsoft Defender for Office 365, and implementation of phishing-resistant MFA methods such as FIDO2 or certificate-based authentication.
Action Items
- Educate users on recognizing sophisticated phishing lures
- Deploy advanced anti-phishing solutions like Microsoft Defender for Office 365
- Implement phishing-resistant MFA methods such as FIDO2
Original Article Brief Intro
Microsoft Security Blog · 2026-05-04 · Incidents: Multi-stage phishing campaign uses AiTM tactics to bypass MFA and steal authentication tokens.
Related Terms and Notes
Techniques / TTPs
- AiTM — Adversary-in-the-middle attacks intercept authentication sessions to steal tokens.
- Credential Theft
- Phishing
Context Notes
- Adversary-in-the-middle
- AiTM
- MFA Bypass — Techniques used to circumvent multi-factor authentication protections.
- Microsoft Defender