CyberSecurityNews

Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails


Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes.

The campaign turns a voicemail alert into a route for financial fraud, even when multi-factor authentication is enabled.

The messages imitate an automated call notification and invite recipients to open a voicemail portal.

A click passes through redirect services before reaching a fake sign-in page that relays the real Microsoft login process, as in the new AiTM attack campaign.

Arctic Wolf analysts identified activity across healthcare, education, manufacturing, government, and professional-services organizations in North America and Europe.

Redacted phishing email showing the voicemail notification lure (Source – Arctic Wolf)

In July, hundreds of organizations received the emails, with intrusions found in varied environments.

Arctic Wolf said in a report shared with Cyber Security News (CSN) that the operation overlaps with Microsoft’s Storm-2755, known as Payroll Pirates.

Rather than immediately send fraudulent messages, operators mostly preserve access, identify finance staff, and collect information that could enable later payroll abuse.

Payroll Pirates Hijack Microsoft 365 Sessions

The initial lure carries a Microsoft logo, invented caller details, and a subject following the format “[Organization] :ATTN: Review messages. Ref id: [random string].”

Its redirect chain abuses Google Meet, Google advertising links, and Amazon S3 hosting to make the malicious destination harder for reputation filters to spot.

At the final site, an adversary-in-the-middle, or AiTM, proxy places itself between the victim and Microsoft.

It forwards genuine authentication pages in real time, then captures the authorization code and session material after the victim completes sign-in and MFA. That is why password resets alone cannot be treated as a complete response.

Multi-stage redirect chain (Source - Arctic Wolf)
Multi-stage redirect chain (Source – Arctic Wolf)

The kit also checks browser details, screen settings, language, location, and automation clues before forwarding visitors.

It then appears to use residential proxy infrastructure near a victim’s country, making later malicious sign-ins resemble ordinary home or mobile connections.

Readers tracking AiTM phishing attacks targeting cloud accounts can see why this relay approach remains difficult to stop with conventional MFA alone.

Within minutes, suspicious OfficeHome sign-ins can begin. Arctic Wolf observed unlikely device and browser combinations, including mobile browsers reported on Windows 10, plus error 90014 in some authentication attempts.

The error was not universal, but its presence with other unusual signals makes it useful for investigation.

Payroll Email Collection Raises Fraud Risk

Between 11 and 24 hours later, attackers began refreshing compromised sessions about every eight hours from changing residential addresses.

The same SessionID persisted while the IP address, network, and geography shifted, pointing to centrally managed automation rather than a normal employee moving between networks.

The actors then used Microsoft Graph to look for payroll, HR, finance, and administrative staff, before opening mail connected to invoices, payments, banking, benefits, and internal documents.

This mirrors the risk described in Microsoft Graph reconnaissance target payroll, where mailbox knowledge can help criminals target salary or direct-deposit processes.

The official Microsoft 365 login page is proxied (Source - Arctic Wolf)
The official Microsoft 365 login page is proxied (Source – Arctic Wolf)

Most cases did not include password changes, new devices, forwarding, or broad outbound phishing. That restraint reduces warning signs.

In a smaller number of cases, operators created rules that moved messages to Deleted Items and marked them read, potentially hiding responses while a financial request is pursued.

Defenders should correlate identity, session, and mailbox logs instead of judging each sign-in alone.

Investigators should look for Outlook activity using Firefox or Python Requests, recurring eight-hour access with one SessionID, Microsoft Graph searches for finance-related roles, and unusual MailItemsAccessed events.

The broader AiTM session hijacking redirect threat shows why payroll teams should independently verify bank-detail changes.

If compromise is suspected, revoke active sessions immediately, reset credentials, and re-register MFA.

Review payroll and HR system activity for the full possible exposure period, especially direct-deposit changes, then check audit logs to establish which messages were accessed and search for the same pattern across accounts.

Longer term, phishing-resistant sign-in methods, managed-device access rules, and Continuous Access Evaluation can reduce the value of stolen sessions.

Organizations should retain non-interactive sign-in logs, because periodic refreshes may otherwise be invisible, and train staff to report unexpected voicemail notices before opening links.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Phishing subject[Organization] :ATTN: Review messages. Ref id: [random string]Voicemail-lure subject format used in inbound messages
URLhttps[:]//meet.google[.]com/linkredirect?dest=https[:]//www.google[.]com/url?q=amp/adservice[.]google.com.ph/ddm/clk/424929466;226923624;r;u=ds&sv1=64195420186&sv2=3261659123742877&sv3=6702577448695742699&gclid=EAIaIQobChMIurHiwbHn8gIVBZ53Ch2TZAIsEAQYASABEgKAL_D_BwE;?//s3[.]us-east-1.amazonaws.com/amzn-5646353653563view/urlExample multi-stage phishing redirect
Domainogads-pa[.]clients6[.]google[.]comGoogle Ads-related domain resolved in redirect sequence
Domainep1[.]adtrafficquality[.]googleGoogle Ads-related domain resolved before phishing infrastructure
Domainep2[.]adtrafficquality[.]googleGoogle Ads-related domain resolved before phishing infrastructure
Redirector domainidp[.]keyreniao[.]comAiTM redirector observed in campaign activity
Redirector domainidp[.]korminel[.]comAiTM redirector observed in campaign activity
Redirector domainidp[.]kualabemo[.]comAiTM redirector observed in campaign activity
Proxy domainmslogin[.]milocaroline[.]comAiTM authentication proxy
Proxy domainmsonline[.]logicalineonline[.]comAiTM authentication proxy
Proxy domainmsauth[.]monlinelogicaline[.]comAiTM authentication proxy
Lookalike domainoffice[.]ofrecie[.]comMisspelled Office-themed domain pattern
URL path/st_58200519/class_identifier.phpBrowser-fingerprinting endpoint on phishing infrastructure
Domainapi[.]country[.]isGeolocation API queried by phishing-kit JavaScript
HTTP headerserver: openresty/1.31.1.1Response header associated with AiTM proxy and fingerprinting endpoint
HTTP headerx-powered-by: ExpressResponse header associated with AiTM proxy root
HTTP headerx-powered-by: PHP/8.2.32Response header associated with fingerprinting endpoint
User-AgentFirefox/131.0Anomalous Outlook sign-in user agent
User-AgentFirefox/151.0Additional anomalous Outlook sign-in user agent
User-AgentPython RequestsUser agent observed in recurring session-maintenance activity
User-Agentaxios/1.18.1User agent linked to Microsoft Graph reconnaissance
Mail access pairingClientAppId: 5d661950-3475-41cd-a2c3-d671a3162bc1; APIId: c999ed3e-27ae-4cb3-b3a2-46b056af63d3High-confidence MailItemsAccessed indicator
Mail access user agentClient=REST;Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:131.0) Gecko/20100101 Firefox/131.0User agent associated with suspicious mailbox collection
Entra sign-in signalerrorCode: 90014; appDisplayName: OfficeHomeRare authentication error pattern associated with campaign activity
Graph endpointhttps[:]//graph.microsoft[.]com/v1.0/users?$top=999Tenant-wide user-enumeration query
Graph endpointhttps[:]//graph.microsoft[.]com/v1.0/meMicrosoft Graph endpoint queried during reconnaissance
ASNAS27176, Datawagon LLCHosting provider observed during interactive inbox-rule activity

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world



Source link