Back to Intel

Intel Node

Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise

lowadvisory2026-05-04T15:00:00+00:00source excerpt
tradecraftwindowsidentityemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Microsoft Defender Research observed a large-scale credential theft campaign that exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker-controlled domains. The post Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise appeared first on Microsoft Security Blog .

In this article Multi-step social engineering campaign leading to credential theft Mitigation and protection guidance Microsoft Defender detections Hunting queries Indicators of compromise Phishing campaigns continue to improve sophistication and refinement in blending social engineering, delivery and hosting infrastructure, and authentication abuse to remain effective against evolving security controls.

A large-scale credential theft campaign observed by Microsoft Defender Research exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker-controlled domains.

Read Original Source