CodeStorm Phishing Campaign Exploits M365 Accounts for Enhanced Attacks
Article Content
- •CodeStorm phishing campaign targets Microsoft 365 tenants using compromised accounts.
- •Attackers employ an AiTM phishing kit with rotating frontends to evade detection.
- •The campaign is ongoing, affecting multiple organizations and bypassing traditional email filters.
A phishing campaign attributed to the CodeStorm group is targeting Microsoft 365 tenants by leveraging compromised accounts. Attackers are using a tenant-aware AiTM phishing kit that employs rotating frontends and backend replay behavior, making it difficult for secure email gateways to detect. This method allows malicious emails to bypass traditional filters, increasing the likelihood of successful phishing attempts. The campaign's scope includes multiple organizations, with a focus on exploiting legitimate M365 accounts to enhance the credibility of phishing messages. As of June 23, 2026, the campaign is ongoing, and organizations are urged to remain vigilant against these sophisticated phishing tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…