Hackers Use AiTM Session Hijacking to Redirect Employee Salaries in New Storm-2755 Campaign
ID: 4c1aaf00-a679-5ae9-96c1-b3d90d802f65
STIX ID: report--4c1aaf00-a679-5ae9-96c1-b3d90d802f65
Feed Name: cybersecurityNews.com
Storm-2755 is running a financially motivated AiTM campaign that targets Canadian employees via SEO-poisoned search results and malvertising to capture Microsoft 365 credentials and live session tokens. The group uses a rogue domain (bluegraintours.com), relays tokens via Axios (v1.7.9) — reportedly leveraging CVE-2025-27152 — then accesses mailboxes to socially engineer HR or directly update payroll in HR platforms, renewing stolen sessions and creating inbox rules to evade detection and steal salary payments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
