The attack begins with phishing emails impersonating voicemail notifications that direct victims through a multi-stage redirect chain abusing legitimate services, including Google Meet, Google Ads infrastructure, and Amazon S3, before ultimately reaching an attacker-controlled AiTM proxy. The proxy relays Microsoft's legitimate authentication flow, allowing attackers to intercept authenticated session tokens without stealing passwords directly or defeating MFA. The phishing infrastructure also fingerprints victim browsers and geolocates users, likely to improve the realism of subsequent malicious sign-ins.
Following compromise, the attackers maintain access by periodically refreshing stolen sessions approximately every eight hours using residential proxy networks. They primarily enumerate users involved in payroll, HR, finance, and administrative roles via Microsoft Graph before collecting mailbox contents related to invoices, payroll, banking, and financial operations. Most observed intrusions avoid traditional BEC activities such as password changes or outbound phishing, instead focusing on stealthy email collection, although limited cases included malicious inbox rules to hide targeted messages.