Skip to content
ThreatCluster

CodeStorm Phishing Campaign Exploits M365 Accounts for Enhanced Attacks

First seen 23 Jun 2026, 10:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 24, 2026 at 10:15 UTC
  • CodeStorm phishing campaign targets Microsoft 365 tenants using compromised accounts.
  • Attackers employ an AiTM phishing kit with rotating frontends to evade detection.
  • The campaign is ongoing, affecting multiple organizations and bypassing traditional email filters.

A phishing campaign attributed to the CodeStorm group is targeting Microsoft 365 tenants by leveraging compromised accounts. Attackers are using a tenant-aware AiTM phishing kit that employs rotating frontends and backend replay behavior, making it difficult for secure email gateways to detect. This method allows malicious emails to bypass traditional filters, increasing the likelihood of successful phishing attempts. The campaign's scope includes multiple organizations, with a focus on exploiting legitimate M365 accounts to enhance the credibility of phishing messages. As of June 23, 2026, the campaign is ongoing, and organizations are urged to remain vigilant against these sophisticated phishing tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 89d ago How this analysis works

Timeline

2026-06-23
CodeStorm phishing campaign reported
A multi-organization phishing campaign using compromised M365 accounts has been identified, employing sophisticated techniques to evade detection.
Gbhackers
2026-06-23
Attackers hijack legitimate M365 accounts
Hackers are abusing real M365 accounts to launch phishing attacks, allowing emails to bypass security filters.
Cybersecuritynews

More articles in this cluster (2)