Payroll Pirates Abuse AiTM Phishing to Compromise Microsoft 365

Red | Attack
Payroll Pirates Abuse AiTM Phishing to Compromise Microsoft 365 | TA2026229

Summary

Payroll Pirates, alias Storm-2755, is an active, financially motivated phishing operation first seen in July 2026 that hijacks Microsoft 365 accounts to search finance and payroll mailboxes quietly across the United States, Canada, and Europe. The threat actor targets Healthcare, Education, Manufacturing, Government, and Professional Services organizations. Victims receive fake voicemail notification emails that route them through a chain of trusted Google and Amazon services to an adversary-in-the-middle (AiTM) page that proxies the real Microsoft login and steals the session, even when multi-factor authentication is enabled. Using rotating residential proxies to blend in as ordinary home traffic, the attackers keep access alive on an eight-hour refresh cycle, use the Microsoft Graph API to locate payroll, HR, and finance staff, and collect emails about payments, banking, and direct deposits, ultimately positioning themselves to reroute salary payments to accounts they control.

Attack Details

#1 Voicemail Lure and Redirect Chain

Payroll Pirates start with phishing emails that look like a voicemail notification. Each email uses a Microsoft logo and fake call details, caller ID, date, length, and a reference number to feel real and urgent. When the victim clicks the "OPEN [Organization] VOICEMAIL PORTAL" button, they are bounced through several trusted services (Google Meet, Google ad links, and a file hosted on Amazon S3) so email filters don't flag the link. The final page is a fake Microsoft login run by the attacker, sitting on a lookalike domain, usually a Microsoft-style or misspelled "Office" name registered only days earlier.

#2 AiTM Session Theft Bypasses MFA

That fake page is an adversary-in-the-middle (AiTM) proxy: instead of just stealing a password, it passes the victim's login straight to the real Microsoft in real time. So even with MFA turned on, once the victim signs in, the attacker captures the live session token and gets in without being asked for a code. Before the login, the page also quietly fingerprints the visitor's browser and checks their country, which the attackers use to pick a matching proxy so their later logins look local. Suspicious sign-ins from these proxies usually appear within minutes.

#3 Persistent Access and Payroll Reconnaissance

From then on, automated logins refresh the stolen session about every eight hours using rotating home-internet (residential proxy) addresses, often showing odd signs like a Firefox or Python client instead of the expected Edge, while keeping the same session ID. With access held, the attackers use the Microsoft Graph API to find staff in payroll, HR, and finance, then read their emails about invoices, payments, banking, and benefits. They mostly stay quiet to avoid setting off alarms, with no password or MFA changes, though in a few cases they created inbox rules to hide messages. The goal is money: the collected information sets them up to reroute salary and direct-deposit payments to their own accounts.

#4 Overlap with Storm-2755 Salary Redirection

This campaign closely overlaps with the Payroll Pirates activity Microsoft tracks as Storm-2755. In an earlier Storm-2755 wave against Canadian employees, the attackers reached victims through poisoned search results and malicious ads instead of email, but stole sessions the same way. After finding finance staff, they emailed HR with "Question about direct deposit" messages, hid the replies with inbox rules, and, when that didn't work, logged into Workday themselves to change bank details and redirect a victim's salary.

Recommendations

01
Revoke Active Sessions Immediately

For any account tied to this campaign, revoke all active sessions and tokens right away; password resets alone do not evict an AiTM-stolen session.

02
Rotate Credentials and Re-Register MFA

Reset passwords and re-enroll MFA for every affected user to invalidate captured authentication material.

03
Audit Payroll and HR Platforms for Direct-Deposit Changes

Review activity in systems such as Workday and ADP across the full suspected dwell period, paying particular attention to bank-account and direct-deposit modifications.

04
Hunt the Eight-Hour Session-Refresh Pattern

Search identity logs for a single SessionID recurring at roughly eight-hour intervals across changing IPs, ASNs, and regions to surface additional compromised accounts.

05
Deploy Phishing-Resistant MFA

Adopt FIDO2 security keys, Windows Hello for Business, or certificate-based authentication, which bind sign-in to the legitimate service and defeat the credential-and-session relay used here.

06
Enforce Managed-Device Access via Conditional Access

Require compliant or Entra hybrid-joined devices so stolen sessions cannot be replayed from unmanaged attacker infrastructure, and review exclusions and legacy authentication paths for gaps.

Potential MITRE ATT&CK TTPs

Resource Development
T1583
Acquire InfrastructureSub-technique: T1583.001 — Domains
Initial Access
T1566
PhishingSub-technique: T1566.002 — Spearphishing Link
Credential Access
T1557
Adversary-in-the-Middle — the fake Microsoft login proxies the real sign-in flow in real time.
Credential Access
T1111
Multi-Factor Authentication Interception — live session capture defeats MFA prompts.
Credential Access
T1539
Steal Web Session Cookie — the live session token is captured at the point of authentication.
Credential Access
T1550
Use Alternate Authentication MaterialSub-technique: T1550.004 — Web Session Cookie
Defense Evasion
T1036
MasqueradingSub-technique: T1036.005 — Match Legitimate Name or Location
Defense Evasion
T1684
Social EngineeringSub-technique: T1684.001 — Impersonation
Command and Control
T1090
ProxySub-technique: T1090.002 — External Proxy
Discovery
T1087
Account DiscoverySub-technique: T1087.004 — Cloud Account
Collection
T1114
Email CollectionSub-technique: T1114.002 — Remote Email Collection

Indicators of Compromise (IOCs)

Type Value
Domains
ogads-pa[.]clients6[.]google[.]comep1[.]adtrafficquality[.]googleep2[.]adtrafficquality[.]googleres[.]public[.]onecdn[.]static[.]microsoftidp[.]keyreniao[.]commslogin[.]milocaroline[.]comapi[.]country[.]isidp[.]korminel[.]comidp[.]kualabemo[.]comint[.]camberwolis[.]commsauth[.]monlinelogicaline[.]commsonline[.]logicalineonline[.]comoffice[.]ofreace[.]comoffice[.]ofercarc[.]comoffice[.]ofrecie[.]comoffice[.]ofreice[.]comoffice[.]ofrecre[.]comoffice[.]ocrifere[.]comoffice[.]ocifire[.]comlogin[.]oficarine[.]comlogin-microsoftonline[.]offirmtm[.]comwisemediapa-ttern[.]digitalsky2025forge[.]digitalskyprimeworks[.]digital1systemsevolve[.]digitalxsyst-emsquantum[.]digitaltec-hnoplatform2025[.]digitalevolveelevateunion[.]digitaloffirmtm[.]comkeyreniao[.]comkorminel[.]comkualabemo[.]commilocaroline[.]commonlinelogicaline[.]comlogicalineonline[.]comofrecie[.]comofreace[.]comofreice[.]comofrecre[.]comofercarc[.]comocrifere[.]comocifire[.]comoficarine[.]com
URLs
hxxps[:]//meet[.]google[.]com/linkredirect?dest=hxxps[:]//www[.]google[.]com/url?q=amp/adservice[.]google[.]com[.]ph/ddm/clk/424929466;226923624;r;u=ds&sv1=64195420186&sv2=3261659123742877&sv3=6702577448695742699&gclid=EAIaIQobChMIurHiwbHn8gIVBZ53Ch2TZAIsEAQYASABEgKAL_D_BwE;?//s3[.]us-east-1[.]amazonaws[.]com/amzn-5646353653563view/urlhxxps[:]//graph[.]microsoft[.]com/v1[.]0/users?$top=999hxxps[:]//graph[.]microsoft[.]com/v1[.]0/me
IPv4
142[.]250[.]137[.]155142[.]250[.]137[.]156142[.]250[.]137[.]157142[.]250[.]137[.]154192[.]178[.]192[.]132187[.]124[.]129[.]44153[.]92[.]1[.]166104[.]26[.]0[.]226104[.]26[.]1[.]226172[.]67[.]75[.]19972[.]62[.]0[.]18131[.]97[.]76[.]103177[.]7[.]56[.]248194[.]5[.]157[.]20424[.]252[.]167[.]6976[.]216[.]220[.]21570[.]108[.]9[.]117172[.]58[.]132[.]24136[.]50[.]134[.]1108[.]147[.]103[.]6267[.]250[.]183[.]23068[.]42[.]211[.]5797[.]165[.]174[.]15824[.]224[.]34[.]191172[.]59[.]214[.]23097[.]85[.]102[.]3
IPv6
2607[:]fb91[:]4[:]4df6[:]431d[:]cce[:]acca[:]39392600[:]4040[:]a33a[:]8e00[:]8121[:]ff13[:]8c19[:]736e2603[:]6013[:]7e00[:]be3a[:]bac2[:]4575[:]6826[:]9b79

References

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.