Payroll Pirate Campaign Uses AiTM Session Hijacking to Bypass MFA and Redirect Salaries
ID: d608d925-0f03-515d-ae64-5ad589bf3f99
STIX ID: report--d608d925-0f03-515d-ae64-5ad589bf3f99
Feed Name: GBHackers
This report outlines the "Payroll Pirate" campaign in which attackers target payroll and HR administrators using tailored reconnaissance, phishing on lookalike domains, and AiTM proxies to capture MFA tokens and hijack live sessions to modify payees and siphon funds; operators favor small transfers, timing near payroll windows, and log/notification tampering to evade detection. The report enumerates technical indicators (unexpected 302 redirects, mismatched TLS, intermediary domains), emphasizes phishing-resistant and origin-bound authentication (WebAuthn/hardware keys), step-up verification and dual-approval for payment changes, and recommends behavioral and transactional monitoring to detect such attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
