---
title: "Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms"
url: https://daily.dev/posts/microsoft-flags-multi-stage-aitm-phishing-and-bec-attacks-targeting-energy-firms-6taou8gqt
source_url: https://thehackernews.com/2026/01/microsoft-flags-multi-stage-aitm.html
type: article
source: "The Hacker News"
published: 2026-01-23T08:35:37.997Z
updated: 2026-02-27T20:46:43.428Z
tags: ["cyber", "microsoft", "authentication", "phishing", "sharepoint"]
reading_time: 6
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms

**[The Hacker News](https://daily.dev/sources/thn)** · 6 min read · 0 upvotes · 0 comments

## Summary

Microsoft has identified a sophisticated multi-stage phishing campaign targeting energy sector organizations. Attackers abuse SharePoint file-sharing to deliver phishing payloads, steal credentials and session cookies through adversary-in-the-middle techniques, then create inbox rules to maintain persistence. The compromised accounts are used to send large-scale phishing emails to internal and external contacts. Password resets alone cannot stop these attacks; organizations must revoke active session cookies and remove malicious inbox rules. The campaign exemplifies the growing trend of abusing trusted platforms like SharePoint, Google Drive, and AWS to appear legitimate and evade detection.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thehackernews.com/2026/01/microsoft-flags-multi-stage-aitm.html>

## Similar posts on daily.dev

- [Multi Brand Themed Phishing Campaign Harvests Credentials](https://daily.dev/posts/multi-brand-themed-phishing-campaign-harvests-credentials-k0xani0lt) · Cyble · 0 upvotes · 0 comments
- [New phishing attack leverages PDFs and Dropbox](https://daily.dev/posts/new-phishing-attack-leverages-pdfs-and-dropbox-pdtkrgw7z) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#microsoft](https://daily.dev/tags/microsoft), [#authentication](https://daily.dev/tags/authentication), [#phishing](https://daily.dev/tags/phishing), [#sharepoint](https://daily.dev/tags/sharepoint)

[View this post on daily.dev](https://daily.dev/posts/microsoft-flags-multi-stage-aitm-phishing-and-bec-attacks-targeting-energy-firms-6taou8gqt)
