Arctic Wolf Labs, the research division of Arctic Wolf, identified and analyzed a widespread AitM phishing campaign targeting Microsoft 365 accounts. Their investigation revealed the use of residential proxies, six-stage redirection chains, and Microsoft Graph API abuse to steal payroll and finance emails.