Payroll Pirates Phishing Campaign Targets Microsoft 365 Financial Workflows (Campaign)
ID: 225df50b-2274-5955-b12d-c4702cc93a88
STIX ID: report--225df50b-2274-5955-b12d-c4702cc93a88
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-08-07
Date Updated: 2026-08-10
Author: [email protected] (Wiz Threat Research)
Payroll Pirates is a phishing campaign that impersonates voicemail notifications and uses multi-stage redirects through legitimate services (Google Meet, Google Ads, Amazon S3) to land victims on an attacker-controlled AiTM proxy that relays Microsoft authentication and captures session tokens without stealing passwords. The actors fingerprint and geolocate victims, refresh stolen sessions every ~8 hours using residential proxies, and use Microsoft Graph to enumerate payroll, HR, finance, and admin accounts to quietly collect mailbox contents related to invoices, payroll, banking, and financial operations, with occasional use of malicious inbox rules to hide messages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
