hundreds of organizations
A large-scale and financially motivated adversary-in-the-middle (AitM) phishing campaign is actively targeting Microsoft 365 accounts across hundreds of organizations. The attack is attributed to threat clusters tracked as Storm-2657 and Storm-2755 (also known as Payroll Pirates). The campaign begins with voicemail-themed phishing emails that lure victims through a multi-stage redirection chain, ultimately landing them on a sophisticated AitM phishing site. This site acts as a proxy, capturing the user's credentials and, critically, their multi-factor authentication (MFA) session token in real-time. After hijacking the account, the attackers use residential proxies to blend in with normal traffic and automated tooling to maintain the session. Their primary goal is to perform reconnaissance within the victim's mailbox, searching for and exfiltrating sensitive emails and documents related to payroll, invoices, and banking, with the ultimate aim of payroll diversion.
This campaign demonstrates a clear, financially motivated objective executed with sophisticated tools and techniques designed to bypass modern security controls.
The combination of AitM phishing, residential proxy usage, and API-based reconnaissance makes this a highly effective campaign.
T1566.002 - Spearphishing Link: The initial email with the malicious link.T1110.004 - Credential Stuffing: The use of an AitM proxy to defeat MFA and steal session tokens.T1539 - Steal Web Session Cookie: The primary goal of the AitM phishing page.T1090.002 - External Proxy: Use of residential proxies to obscure the origin of the attack.T1114.002 - Remote Email Collection: Using the Graph API to search for and exfiltrate emails.T1078.004 - Cloud Accounts: The attackers use the compromised cloud account to conduct their operations.The campaign has targeted hundreds of organizations across healthcare, education, manufacturing, and government, primarily in the U.S., Canada, and Europe.
No specific IOCs were provided in the source articles.
Microsoft GraphSearch-Mailbox or Graph API search queriesDomestic User Activity Analysis.Deploy phishing-resistant MFA (FIDO2) to technically prevent session hijacking via AitM proxies.
Train users to be suspicious of unexpected login prompts and voicemail-themed phishing emails.
The most effective technical countermeasure against the 'Payroll Pirates' AitM campaign is to implement phishing-resistant Multi-factor Authentication (D3-MFA). Specifically, organizations should migrate from phishable MFA methods like SMS and push notifications to FIDO2-based authenticators (e.g., YubiKeys, Windows Hello for Business). FIDO2 binds the authentication process to the specific domain, meaning a credential cannot be used on a lookalike phishing site. When a user is tricked into visiting the attacker's AitM proxy, the browser and security key will refuse to complete the authentication, technically breaking the attack chain. This moves the defense from relying on user vigilance to a robust, technical control that neutralizes the core of the threat.
To detect a successful account takeover, security teams must perform continuous Web Session Activity Analysis (D3-WSAA), particularly for Microsoft 365. This involves creating SIEM rules to detect the attacker's post-compromise behavior. A high-fidelity alert should be triggered when a user session, especially one originating from a residential ISP or an anomalous location, begins making programmatic queries via the Microsoft Graph API. Specifically, monitor for API calls related to searching mailboxes (/messages?$search=) with financial keywords like 'payroll' or 'invoice'. A normal user interacts with their mailbox via a browser or Outlook client; they do not typically use the Graph API directly to perform keyword searches. This behavioral mismatch is a strong indicator of a compromised account being used for reconnaissance by the 'Payroll Pirates' group.
To stop the attack at the initial email stage, organizations need advanced URL Analysis (D3-UA) capabilities in their email security gateway. The 'Payroll Pirates' campaign uses a multi-stage redirection chain involving legitimate services like Google Meet and Amazon S3 to evade simple URL blocklists. An effective email security solution must be able to 'detonate' or follow these links in a sandbox environment to their final destination. The system should analyze the entire chain and identify that it ultimately leads to a newly registered domain hosting a phishing kit. By analyzing the final landing page for credential fields and signs of an AitM proxy, the security gateway can block the email before it ever reaches the user's inbox, preventing the social engineering attempt from even beginning.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.