Storm-2755 Uses AiTM Hijacking to Divert Employee Salaries
ID: 8a26718d-0f23-5adc-a9da-94f449bf7d78
STIX ID: report--8a26718d-0f23-5adc-a9da-94f449bf7d78
Feed Name: GBHackers
Microsoft-tracked Storm-2755 is a financially motivated campaign targeting Canadian users that uses SEO poisoning and malvertising to lure victims to spoofed Microsoft 365 sign-in pages, perform AiTM session hijacking to capture passwords and session tokens, and replay those tokens (observed with the Axios 1.7.9 user-agent) to access Office/HR services and change payroll direct-deposit settings so salaries are routed to attacker accounts; recommended mitigations include immediate token revocation, forced credential/MFA resets, phishing-resistant MFA (FIDO2/WebAuthn), Conditional Access with adaptive session lifetimes, Continuous Access Evaluation, and monitoring for suspicious user‑agents and inbox rule creation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
