Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes.
The campaign turns a voicemail alert into a route for financial fraud, even when multi-factor authentication is enabled.
The messages imitate an automated call notification and invite recipients to open a voicemail portal.
A click passes through redirect services before reaching a fake sign-in page that relays the real Microsoft login process, as in the new AiTM attack campaign.
Arctic Wolf analysts identified activity across healthcare, education, manufacturing, government, and professional-services organizations in North America and Europe.
In July, hundreds of organizations received the emails, with intrusions found in varied environments.
Arctic Wolf said in a report shared with Cyber Security News (CSN) that the operation overlaps with Microsoft’s Storm-2755, known as Payroll Pirates.
Rather than immediately send fraudulent messages, operators mostly preserve access, identify finance staff, and collect information that could enable later payroll abuse.
Payroll Pirates Hijack Microsoft 365 Sessions
The initial lure carries a Microsoft logo, invented caller details, and a subject following the format “[Organization] :ATTN: Review messages. Ref id: [random string].”
Its redirect chain abuses Google Meet, Google advertising links, and Amazon S3 hosting to make the malicious destination harder for reputation filters to spot.
At the final site, an adversary-in-the-middle, or AiTM, proxy places itself between the victim and Microsoft.
It forwards genuine authentication pages in real time, then captures the authorization code and session material after the victim completes sign-in and MFA. That is why password resets alone cannot be treated as a complete response.
.webp)
The kit also checks browser details, screen settings, language, location, and automation clues before forwarding visitors.
It then appears to use residential proxy infrastructure near a victim’s country, making later malicious sign-ins resemble ordinary home or mobile connections.
Readers tracking AiTM phishing attacks targeting cloud accounts can see why this relay approach remains difficult to stop with conventional MFA alone.
Within minutes, suspicious OfficeHome sign-ins can begin. Arctic Wolf observed unlikely device and browser combinations, including mobile browsers reported on Windows 10, plus error 90014 in some authentication attempts.
The error was not universal, but its presence with other unusual signals makes it useful for investigation.
Payroll Email Collection Raises Fraud Risk
Between 11 and 24 hours later, attackers began refreshing compromised sessions about every eight hours from changing residential addresses.
The same SessionID persisted while the IP address, network, and geography shifted, pointing to centrally managed automation rather than a normal employee moving between networks.
The actors then used Microsoft Graph to look for payroll, HR, finance, and administrative staff, before opening mail connected to invoices, payments, banking, benefits, and internal documents.
This mirrors the risk described in Microsoft Graph reconnaissance target payroll, where mailbox knowledge can help criminals target salary or direct-deposit processes.
.webp)
Most cases did not include password changes, new devices, forwarding, or broad outbound phishing. That restraint reduces warning signs.
In a smaller number of cases, operators created rules that moved messages to Deleted Items and marked them read, potentially hiding responses while a financial request is pursued.
Defenders should correlate identity, session, and mailbox logs instead of judging each sign-in alone.
Investigators should look for Outlook activity using Firefox or Python Requests, recurring eight-hour access with one SessionID, Microsoft Graph searches for finance-related roles, and unusual MailItemsAccessed events.
The broader AiTM session hijacking redirect threat shows why payroll teams should independently verify bank-detail changes.
If compromise is suspected, revoke active sessions immediately, reset credentials, and re-register MFA.
Review payroll and HR system activity for the full possible exposure period, especially direct-deposit changes, then check audit logs to establish which messages were accessed and search for the same pattern across accounts.
Longer term, phishing-resistant sign-in methods, managed-device access rules, and Continuous Access Evaluation can reduce the value of stolen sessions.
Organizations should retain non-interactive sign-in logs, because periodic refreshes may otherwise be invisible, and train staff to report unexpected voicemail notices before opening links.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Phishing subject | [Organization] :ATTN: Review messages. Ref id: [random string] | Voicemail-lure subject format used in inbound messages |
| URL | https[:]//meet.google[.]com/linkredirect?dest=https[:]//www.google[.]com/url?q=amp/adservice[.]google.com.ph/ddm/clk/424929466;226923624;r;u=ds&sv1=64195420186&sv2=3261659123742877&sv3=6702577448695742699&gclid=EAIaIQobChMIurHiwbHn8gIVBZ53Ch2TZAIsEAQYASABEgKAL_D_BwE;?//s3[.]us-east-1.amazonaws.com/amzn-5646353653563view/url | Example multi-stage phishing redirect |
| Domain | ogads-pa[.]clients6[.]google[.]com | Google Ads-related domain resolved in redirect sequence |
| Domain | ep1[.]adtrafficquality[.]google | Google Ads-related domain resolved before phishing infrastructure |
| Domain | ep2[.]adtrafficquality[.]google | Google Ads-related domain resolved before phishing infrastructure |
| Redirector domain | idp[.]keyreniao[.]com | AiTM redirector observed in campaign activity |
| Redirector domain | idp[.]korminel[.]com | AiTM redirector observed in campaign activity |
| Redirector domain | idp[.]kualabemo[.]com | AiTM redirector observed in campaign activity |
| Proxy domain | mslogin[.]milocaroline[.]com | AiTM authentication proxy |
| Proxy domain | msonline[.]logicalineonline[.]com | AiTM authentication proxy |
| Proxy domain | msauth[.]monlinelogicaline[.]com | AiTM authentication proxy |
| Lookalike domain | office[.]ofrecie[.]com | Misspelled Office-themed domain pattern |
| URL path | /st_58200519/class_identifier.php | Browser-fingerprinting endpoint on phishing infrastructure |
| Domain | api[.]country[.]is | Geolocation API queried by phishing-kit JavaScript |
| HTTP header | server: openresty/1.31.1.1 | Response header associated with AiTM proxy and fingerprinting endpoint |
| HTTP header | x-powered-by: Express | Response header associated with AiTM proxy root |
| HTTP header | x-powered-by: PHP/8.2.32 | Response header associated with fingerprinting endpoint |
| User-Agent | Firefox/131.0 | Anomalous Outlook sign-in user agent |
| User-Agent | Firefox/151.0 | Additional anomalous Outlook sign-in user agent |
| User-Agent | Python Requests | User agent observed in recurring session-maintenance activity |
| User-Agent | axios/1.18.1 | User agent linked to Microsoft Graph reconnaissance |
| Mail access pairing | ClientAppId: 5d661950-3475-41cd-a2c3-d671a3162bc1; APIId: c999ed3e-27ae-4cb3-b3a2-46b056af63d3 | High-confidence MailItemsAccessed indicator |
| Mail access user agent | Client=REST;Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:131.0) Gecko/20100101 Firefox/131.0 | User agent associated with suspicious mailbox collection |
| Entra sign-in signal | errorCode: 90014; appDisplayName: OfficeHome | Rare authentication error pattern associated with campaign activity |
| Graph endpoint | https[:]//graph.microsoft[.]com/v1.0/users?$top=999 | Tenant-wide user-enumeration query |
| Graph endpoint | https[:]//graph.microsoft[.]com/v1.0/me | Microsoft Graph endpoint queried during reconnaissance |
| ASN | AS27176, Datawagon LLC | Hosting provider observed during interactive inbox-rule activity |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

