logo

New Storm-2755 Campaign Redirects Salaries via Session Hijacking

ID: 798e6853-68d7-54a2-adbf-59c3805bba88

STIX ID: report--798e6853-68d7-54a2-adbf-59c3805bba88

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-04-13

Author: Varshini

...
...

Microsoft DART warns of Storm-2755, a Canada‑targeted payroll‑fraud campaign that uses SEO poisoning and malvertising to push victims to an attacker-controlled Azure/Office 365 proxy (bluegraintours.com) to perform AiTM token capture; the actor replays harvested session/OAuth tokens (not just passwords), abuses Axios as a session-relay, and is observed exploiting CVE‑2025‑27152 (SSRF) to pivot during replay. Stolen sessions remain usable for up to ~30 days, enabling quiet direct‑deposit theft; Microsoft recommends revoking tokens/sessions, removing mailbox rules, resetting credentials/MFA, and enforcing phishing‑resistant MFA, Conditional Access session controls, and CAE.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.