The Payroll Pirate Campaign Leverages AiTM Session Hijacking to Target HR Departments
ID: 38975ef9-aa5b-59d3-903b-30fdf551fb46
STIX ID: report--38975ef9-aa5b-59d3-903b-30fdf551fb46
Feed Name: securityonline.info
### Executive Summary The report outlines an active "Payroll Pirate" campaign that steals payroll funds by hijacking authenticated Microsoft 365 sessions (AiTM/token replay), enumerating directories via Microsoft Graph API to identify HR/payroll accounts, and manipulating payments; activity is attributed to Storm-2755 and Storm-2657 and affects multiple sectors. Attackers use a split infrastructure (US mobile for auth, Canadian residential for directory access) to avoid detection and leave minimal endpoint artifacts; recommended defenses include phishing-resistant FIDO2/Windows Hello auth, Graph audit telemetry monitoring, and auditing enterprise OAuth apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
