
01 · Overview
Payroll Pirates, alias Storm-2755, is an active, financially motivated phishing operation first seen in July 2026 that hijacks Microsoft 365 accounts to search finance and payroll mailboxes quietly across the United States, Canada, and Europe. The threat actor targets Healthcare, Education, Manufacturing, Government, and Professional Services organizations. Victims receive fake voicemail notification emails that route them through a chain of trusted Google and Amazon services to an adversary-in-the-middle (AiTM) page that proxies the real Microsoft login and steals the session, even when multi-factor authentication is enabled. Using rotating residential proxies to blend in as ordinary home traffic, the attackers keep access alive on an eight-hour refresh cycle, use the Microsoft Graph API to locate payroll, HR, and finance staff, and collect emails about payments, banking, and direct deposits, ultimately positioning themselves to reroute salary payments to accounts they control.
02 · Technical Breakdown
Payroll Pirates start with phishing emails that look like a voicemail notification. Each email uses a Microsoft logo and fake call details, caller ID, date, length, and a reference number to feel real and urgent. When the victim clicks the "OPEN [Organization] VOICEMAIL PORTAL" button, they are bounced through several trusted services (Google Meet, Google ad links, and a file hosted on Amazon S3) so email filters don't flag the link. The final page is a fake Microsoft login run by the attacker, sitting on a lookalike domain, usually a Microsoft-style or misspelled "Office" name registered only days earlier.
That fake page is an adversary-in-the-middle (AiTM) proxy: instead of just stealing a password, it passes the victim's login straight to the real Microsoft in real time. So even with MFA turned on, once the victim signs in, the attacker captures the live session token and gets in without being asked for a code. Before the login, the page also quietly fingerprints the visitor's browser and checks their country, which the attackers use to pick a matching proxy so their later logins look local. Suspicious sign-ins from these proxies usually appear within minutes.
From then on, automated logins refresh the stolen session about every eight hours using rotating home-internet (residential proxy) addresses, often showing odd signs like a Firefox or Python client instead of the expected Edge, while keeping the same session ID. With access held, the attackers use the Microsoft Graph API to find staff in payroll, HR, and finance, then read their emails about invoices, payments, banking, and benefits. They mostly stay quiet to avoid setting off alarms, with no password or MFA changes, though in a few cases they created inbox rules to hide messages. The goal is money: the collected information sets them up to reroute salary and direct-deposit payments to their own accounts.
This campaign closely overlaps with the Payroll Pirates activity Microsoft tracks as Storm-2755. In an earlier Storm-2755 wave against Canadian employees, the attackers reached victims through poisoned search results and malicious ads instead of email, but stole sessions the same way. After finding finance staff, they emailed HR with "Question about direct deposit" messages, hid the replies with inbox rules, and, when that didn't work, logged into Workday themselves to change bank details and redirect a victim's salary.
03 · Mitigation
For any account tied to this campaign, revoke all active sessions and tokens right away; password resets alone do not evict an AiTM-stolen session.
Reset passwords and re-enroll MFA for every affected user to invalidate captured authentication material.
Review activity in systems such as Workday and ADP across the full suspected dwell period, paying particular attention to bank-account and direct-deposit modifications.
Search identity logs for a single SessionID recurring at roughly eight-hour intervals across changing IPs, ASNs, and regions to surface additional compromised accounts.
Adopt FIDO2 security keys, Windows Hello for Business, or certificate-based authentication, which bind sign-in to the legitimate service and defeat the credential-and-session relay used here.
Require compliant or Entra hybrid-joined devices so stolen sessions cannot be replayed from unmanaged attacker infrastructure, and review exclusions and legacy authentication paths for gaps.
04 · Adversary Tradecraft
05 · Forensic Markers
| Type | Value |
|---|---|
| Domains |
ogads-pa[.]clients6[.]google[.]comep1[.]adtrafficquality[.]googleep2[.]adtrafficquality[.]googleres[.]public[.]onecdn[.]static[.]microsoftidp[.]keyreniao[.]commslogin[.]milocaroline[.]comapi[.]country[.]isidp[.]korminel[.]comidp[.]kualabemo[.]comint[.]camberwolis[.]commsauth[.]monlinelogicaline[.]commsonline[.]logicalineonline[.]comoffice[.]ofreace[.]comoffice[.]ofercarc[.]comoffice[.]ofrecie[.]comoffice[.]ofreice[.]comoffice[.]ofrecre[.]comoffice[.]ocrifere[.]comoffice[.]ocifire[.]comlogin[.]oficarine[.]comlogin-microsoftonline[.]offirmtm[.]comwisemediapa-ttern[.]digitalsky2025forge[.]digitalskyprimeworks[.]digital1systemsevolve[.]digitalxsyst-emsquantum[.]digitaltec-hnoplatform2025[.]digitalevolveelevateunion[.]digitaloffirmtm[.]comkeyreniao[.]comkorminel[.]comkualabemo[.]commilocaroline[.]commonlinelogicaline[.]comlogicalineonline[.]comofrecie[.]comofreace[.]comofreice[.]comofrecre[.]comofercarc[.]comocrifere[.]comocifire[.]comoficarine[.]com |
| URLs |
hxxps[:]//meet[.]google[.]com/linkredirect?dest=hxxps[:]//www[.]google[.]com/url?q=amp/adservice[.]google[.]com[.]ph/ddm/clk/424929466;226923624;r;u=ds&sv1=64195420186&sv2=3261659123742877&sv3=6702577448695742699&gclid=EAIaIQobChMIurHiwbHn8gIVBZ53Ch2TZAIsEAQYASABEgKAL_D_BwE;?//s3[.]us-east-1[.]amazonaws[.]com/amzn-5646353653563view/urlhxxps[:]//graph[.]microsoft[.]com/v1[.]0/users?$top=999hxxps[:]//graph[.]microsoft[.]com/v1[.]0/me |
| IPv4 |
142[.]250[.]137[.]155142[.]250[.]137[.]156142[.]250[.]137[.]157142[.]250[.]137[.]154192[.]178[.]192[.]132187[.]124[.]129[.]44153[.]92[.]1[.]166104[.]26[.]0[.]226104[.]26[.]1[.]226172[.]67[.]75[.]19972[.]62[.]0[.]18131[.]97[.]76[.]103177[.]7[.]56[.]248194[.]5[.]157[.]20424[.]252[.]167[.]6976[.]216[.]220[.]21570[.]108[.]9[.]117172[.]58[.]132[.]24136[.]50[.]134[.]1108[.]147[.]103[.]6267[.]250[.]183[.]23068[.]42[.]211[.]5797[.]165[.]174[.]15824[.]224[.]34[.]191172[.]59[.]214[.]23097[.]85[.]102[.]3 |
| IPv6 |
2607[:]fb91[:]4[:]4df6[:]431d[:]cce[:]acca[:]39392600[:]4040[:]a33a[:]8e00[:]8121[:]ff13[:]8c19[:]736e2603[:]6013[:]7e00[:]be3a[:]bac2[:]4575[:]6826[:]9b79 |
06 · Further Reading
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.