Payroll Pirates: Strange New Tides in Business Email Compromise
ID: b2fd3886-95da-5bd3-a7df-2eb1c8830f80
STIX ID: report--b2fd3886-95da-5bd3-a7df-2eb1c8830f80
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs reports an ongoing, widespread Microsoft 365-focused AiTM phishing campaign that uses voicemail-themed lures and multi-stage redirect chains to proxy legitimate Microsoft authentication, capture authorization material (even when MFA is present), and maintain stolen sessions via geographically matched rotating residential proxies with automated eight-hour refreshes; the actors use Microsoft Graph to enumerate and collect payroll/finance-related mailboxes across multiple sectors and regions, and the bulletin includes technical analysis, IOCs, detection guidance (Entra sign-in anomalies, MailItemsAccessed AppID/APIId pairing, DNS/network indicators) and remediation/hardening recommendations such as phishing-resistant MFA and Conditional Access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
