What is the end goal of your run of the mill phishing attack?

Posted by DeifniteProfessional@reddit | sysadmin | View on Reddit | 51 comments

It's become increasingly common to see Microsoft specific attacks that are designed to get a user to log in, allowing the attacker to gain access, even with MFA enabled. From what I've seen so far, the attacker gets in, then uses the account to bulk send the same payload to more contacts. What's the final goal here? Is it a case of collecting as many business accounts as possible and then start manually running scams from each one after a period of time?