logo

Hackers Use AiTM Session Hijacking to Redirect Employee Salaries in New Storm-2755 Campaign

ID: 4c1aaf00-a679-5ae9-96c1-b3d90d802f65

STIX ID: report--4c1aaf00-a679-5ae9-96c1-b3d90d802f65

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-10

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Storm-2755 is running a financially motivated AiTM campaign that targets Canadian employees via SEO-poisoned search results and malvertising to capture Microsoft 365 credentials and live session tokens. The group uses a rogue domain (bluegraintours.com), relays tokens via Axios (v1.7.9) — reportedly leveraging CVE-2025-27152 — then accesses mailboxes to socially engineer HR or directly update payroll in HR platforms, renewing stolen sessions and creating inbox rules to evade detection and steal salary payments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.