{"id":2266,"date":"2026-08-07T11:00:54","date_gmt":"2026-08-07T11:00:54","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2266"},"modified":"2026-08-07T11:00:54","modified_gmt":"2026-08-07T11:00:54","slug":"microsoft-365-aitm-phishing-hijacks-accounts-to-collect-payroll-and-finance-emails","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2266","title":{"rendered":"Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgH78NjDW1Q_sIk9dwQ1scYlCkNCMutfjGx_9flqrKbE42fEXqvHT8s5EeHTnWjbBGvzCuHPEWStR5r6wjwtIuuHF1hyphenhyphenot22E_Q98xedC1zXVhIhwglw6hLWQs45oSrPKPflK6Tt1BlHTj9iokMPpVaTehuemHGHDLL02cn2sqZJ5iIVstxiVf5IZ5Khodp\/s1700-e365\/ms-phish.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have called attention to an active \u00abwidespread email-driven phishing campaign\u00bb that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.<\/p>\n<p>\u00abThe campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,\u00bb Arctic Wolf Labs <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/payroll-pirates-strange-new-tides-in-business-email-compromise\/\" target=\"_blank\">said<\/a>. \u00abAutomated activity maintains compromised sessions at approximately eight-hour intervals.\u00bb<\/p>\n<p>The activity is assessed to impact organizations across healthcare, education, manufacturing, government, and professional services sectors located in the U.S., Canada, and Europe. It shares tactical overlaps with Payroll Pirate attacks tracked by Microsoft under the moniker Storm-2755.<\/p>\n<p>Payroll Pirates is the designation assigned to a broader financially motivated threat cluster that involves <a href=\"https:\/\/sra.io\/blog\/payroll-pirate-campaign-aitm-session-hijacking-and-microsoft-graph-reconnaissance-across-multiple-client-environments\/\" target=\"_blank\">hijacking<\/a> the accounts of employees to reroute salary payments to attacker-controlled accounts. Some aspects of these campaigns have been documented since early 2025, with Microsoft tracking a related threat as Storm-2657.<\/p>\n<p>Arctic Wolf said it observed hundreds of organizations being targeted by email as part of the latest phishing campaign last month, resulting in successful intrusions spanning a broad range of victim environments.<\/p>\n<p>Attack chains involve the use of voicemail-themed phishing emails to lead victims to AitM decoy pages that act as a proxy for the legitimate Microsoft account authentication flow, while stealthily capturing their credentials and multi-factor authentication (MFA) codes.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>This is accomplished by means of a six-stage redirection chain that employs legitimate and trusted services like Google, Google Meet, Google Ads, and Amazon S3 to sidestep reputation-driven filters. <\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abThe chain begins with a Google Meet linkredirect URL, and continues through Google&#8217;s outbound-link infrastructure before reaching a Campaign Manager \/ddm\/clk dynamic click tracker,\u00bb Arctic Wolf said. \u00abIn the activity we observed, the destination embedded in the tracker URL pointed to an HTML object hosted in an Amazon AWS S3 bucket. The S3-hosted page then redirected the victim to the campaign&#8217;s AitM phishing infrastructure.\u00bb<\/p>\n<p>The phishing pages also employ JavaScript to fingerprint the visiting host, gathering information about the web browser, operating system, screen and window dimensions, browser language, time zone offset, cookie capabilities, WebDriver status, WebGL vendor, and browser API availability. All this information is packaged and sent to a PHP endpoint through an HTTP POST request. The script then redirects the browser to the proxied Microsoft OAuth authorization endpoint.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgjawHPyzxcVaMFSCmvbKM9yj9CC5Re7tuR9hmz7QM7RDyQNe7175m4rYm9V37zVoHB6DODZAuutuR0-P7Yg2ep_DYYT1a45Vdj1KiemkDkfLmaSnvJf_s-1AsR6rc_iZ4QqDdDzeIbLPb2LOLaepIUg57Er8vU7_675bs_OhY-zUGunuoVf4YUoor1YNnF\/s1700-e365\/redirect.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgjawHPyzxcVaMFSCmvbKM9yj9CC5Re7tuR9hmz7QM7RDyQNe7175m4rYm9V37zVoHB6DODZAuutuR0-P7Yg2ep_DYYT1a45Vdj1KiemkDkfLmaSnvJf_s-1AsR6rc_iZ4QqDdDzeIbLPb2LOLaepIUg57Er8vU7_675bs_OhY-zUGunuoVf4YUoor1YNnF\/s1700-e365\/redirect.png\" alt=\"\" border=\"0\" data-original-height=\"800\" data-original-width=\"1200\"\/><\/a><\/div>\n<p>It also queries a geolocation API (\u00abapi.country[.]is\u00bb) for the requester&#8217;s country code, and stores the result in a \u00abrcfh_country\u00bb cookie with a seven-day expiration. Once initial access is obtained, the threat actor abuses the compromised sessions to collect emails from payroll and HR personnel who are involved in financial matters at the enterprise. <\/p>\n<p>What&#8217;s more, controlled testing reveals that the malicious sign-in activity originates within minutes from a residential proxy exit node in the victim&#8217;s country, indicating that the threat actors are possibly leveraging the geolocation data to select geographically matched proxy infrastructure for subsequent logins and evade security controls that otherwise prevent access from unusual IP addresses.<\/p>\n<p>Some of these sign-in events report \u00abimplausible browser and operating-system combinations,\u00bb such as mobile versions of Apple Safari or Google Chrome on Windows 10.<\/p>\n<p>\u00abTypically, 11 to 24 hours after the initial anomalous activity, malicious sign-ins began recurring at eight-hour intervals from rotating residential proxy addresses,\u00bb Arctic Wolf added. \u00abThese events reported Microsoft Outlook as the client application but used Firefox 131.0, Firefox 151.0, or occasionally Python Requests user agents rather than the expected Edge user agent.\u00bb<\/p>\n<p>\u00abThe recurring sign-ins retained the same SessionID while the source IP address, ASN, and geographic location changed, providing further evidence that centralized automation was refreshing each compromised session independently.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Like in the case of Storm-2755, the threat actors have been found relying on the Microsoft Graph API to enumerate tenant users associated with payroll, HR, finance, and administrative functions, and then accessing messages related to payroll, invoices, payments, banking, benefits, and internal documents..<\/p>\n<p>In most intrusions investigated by the security vendor, the attackers are said to have restricted their post-compromise actions to session maintenance, reconnaissance, and mailbox collection. No other activity, including MFA-method changes, device registration, credential modification, lateral phishing, or inbox rule creation, has been observed.<\/p>\n<p>\u00abBy avoiding these common BEC behaviors, the threat actors limited opportunities for early detection based on account modification or outbound email abuse,\u00bb Arctic Wolf added.<\/p>\n<p>That said, a handful of cases involved the attackers engaging in hands-on keyboard activity to create inbox rules that automatically moved certain messages from Inbox to Deleted Items and marked them as read. There is evidence to suggest that the operators intervened selectively for account manipulation, while a centralized automation infrastructure handled other aspects of the attack.<\/p>\n<p>\u00abUsing rotating residential proxies, the threat actor quietly maintained stolen sessions, identified personnel involved in financial workflows, and collected relevant mailbox data through automated activity,\u00bb Arctic Wolf said. \u00abThe delay between initial access and subsequent automation, combined with restrained post-compromise activity, makes the campaign harder to connect to the original phishing event and less likely to trigger existing detections.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have called attention to an active \u00abwidespread email-driven phishing campaign\u00bb that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2267,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[592,392,2943,625,1260,774,147,2944,390],"class_list":["post-2266","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-accounts","tag-aitm","tag-collect","tag-emails","tag-finance","tag-hijacks","tag-microsoft","tag-payroll","tag-phishing"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2266","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2266"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2266\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2267"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2266"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2266"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2266"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}