Threat actors in the AitM phishing campaign use the Microsoft Graph API to enumerate tenant users associated with payroll, HR, finance, and administrative functions, and to access messages related to payroll, invoices, payments, banking, and benefits.