Multi-Stage 'Code of Conduct' Phishing Campaign Leads to AiTM Token Compromise (Microsoft Defender Research, April 2026) — Threadlinqs Intelligence
As of 2026-05-30, Multi-Stage 'Code of Conduct' Phishing Campaign Leads to AiTM Token Compromise (Microsoft Defender Research, April 2026) is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0454 · Severity: HIGH · Status: MONITORING · Category: PHISHING
Microsoft Defender Research disclosed a large-scale credential-theft campaign run April 14-16, 2026 that targeted 35,000 users across 13,000 organizations in 26 countries (92% United States).
Between 06:51 UTC on April 14, 2026 and 03:54 UTC on April 16, 2026, Microsoft Defender Experts and Microsoft Threat Intelligence observed a high-volume credential phishing campaign that combined social-engineering, anti-analysis tooling, and AiTM token theft. The operation targeted more than 35,000 users across 13,000+ tenants in 26 countries, with 92% of impacted users located in the United States. Healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology and software (11%) made up the bulk of the victim pool.
Lures impersonated internal compliance, regulatory, or HR functions. Senders used display names such as 'Internal Regulatory COC', 'Workforce Communications', and 'Team Conduct Report', and subjects such as 'Internal case log issued under conduct policy' and 'Reminder: employer opened a non-compliance case log'. Each message carried a PDF attachment (e.g. 'Awareness Case Log File - Monday 13th, April 2026.pdf', 'Disciplinary Action - Employee Device Handling Case.pdf') containing a single hyperlink labeled 'Review & Sign'. Several lures were wrapped in a Paubox HIPAA-compliance banner to bait healthcare recipients with familiar branding.
When the victim clicked through, they were redirected to attacker-controlled infrastructure (e.g. compliance-protectionoutlook.de, acceptable-use-policy-calendly.de) fronted by a Cloudflare Turnstile / hCaptcha challenge. The CAPTCHA served as an execution guardrail: automated scanners and headless sandboxes were filtered out, leaving only real users to reach the next stage. A staging page then collected the victim's email address before issuing a second image-selection CAPTCHA. Server-side logic inspected the user agent and referrer to perform a platform-conditional redirect (mobile vs desktop) that delivered a tailored phishing template for each device class.
The terminal page rendered a pixel-perfect Microsoft sign-in dialog hosted on attacker infrastructure. When the victim authenticated, an AiTM reverse-proxy (consistent with Tycoon/Mamba-style phishing-as-a-service kits) brokered the session in real time with login.microsoftonline.com, captured the resulting session and refresh tokens, and bypassed any non-phishing-resistant second factor (SMS, voice call, push approval, or one-time password). Once tokens were exfiltrated, the operators had persistent access to the victim's Microsoft 365 environment as a valid cloud user, enabling downstream business email compromise, mailbox reconnaissance, and OAuth abuse.
Microsoft additionally observed the actors using cloud-hosted Windows VMs as legitimate sending infrastructure, abusing the reputation of mainstream cloud providers to evade SEG (secure email gateway) reputation filters. No nation-state attribution has been published; tradecraft is consistent with financially-motivated phishing-as-a-service crews operating commodity AiTM kits. Defender Research published the analysis on May 4, 2026.
Defenders should treat any recently-issued Microsoft session cookie obtained from a sign-in flow that did not use FIDO2 / Windows Hello / certificate-based authentication as suspect. Recommended mitigations include: enforcing phishing-resistant MFA via Conditional Access, enabling token-protection (CAE) where available, blocking the published domain and sender IOCs at the SEG and proxy, hashing the four PDF SHA-256 IOCs into AV/EDR blocklists, and proactively revoking refresh tokens on any account that interacted with the campaign.
Weaknesses (CWE)
CWE-294, CWE-300, CWE-451, CWE-1021
Target sectors: healthcare, life-sciences, financial-services, professional-services, technology, software
Target regions: United States, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1608, T1585, T1566, T1566, T1078, T1204, T1204, T1656