According to new research from ReliaQuest, threat actors are exploiting Microsoft’s Direct Send functionality in combination with HTTP client tools like Axios to create a “highly efficient attack pipeline” in recent phishing attempts.
According to a study published with The Hacker News, Axios user agent activity increased 241% between June and August 2025, outpacing the 85% growth of all other flagged user agents combined. Axios was responsible for 24.44% of all activity among the 32 flagged user agents that were seen during this period.
Account takeover (ATO) attacks on Microsoft 365 systems were previously reported by Proofpoint in January 2025, which detailed campaigns that used HTTP clients to send HTTP requests and get HTTP answers from web servers.
ReliaQuest told The Hacker News that the tool is frequently used in conjunction with well-known phishing kits, but that there is no proof that these actions are connected read more about Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
