logo

Storm-2755 Uses AiTM Hijacking to Divert Employee Salaries

ID: 8a26718d-0f23-5adc-a9da-94f449bf7d78

STIX ID: report--8a26718d-0f23-5adc-a9da-94f449bf7d78

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-04-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Microsoft-tracked Storm-2755 is a financially motivated campaign targeting Canadian users that uses SEO poisoning and malvertising to lure victims to spoofed Microsoft 365 sign-in pages, perform AiTM session hijacking to capture passwords and session tokens, and replay those tokens (observed with the Axios 1.7.9 user-agent) to access Office/HR services and change payroll direct-deposit settings so salaries are routed to attacker accounts; recommended mitigations include immediate token revocation, forced credential/MFA resets, phishing-resistant MFA (FIDO2/WebAuthn), Conditional Access with adaptive session lifetimes, Continuous Access Evaluation, and monitoring for suspicious user‑agents and inbox rule creation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.