Poisoned “Office 365” search results lead to stolen paychecks
ID: ee361a6f-c42e-5dc8-8079-7ac8bbf44d9b
STIX ID: report--ee361a6f-c42e-5dc8-8079-7ac8bbf44d9b
Feed Name: Help Net Security
### Executive summary Microsoft researchers uncovered Storm-2755, a financially-motivated campaign targeting Canadian employees that uses SEO poisoning, malvertising, and an AiTM proxy to capture Microsoft 365 credentials and session tokens; attackers then impersonate employees or directly access payroll SaaS to change direct-deposit details and steal paychecks. Microsoft recommends FIDO2/WebAuthn, monitoring for Axios user-agent and non-interactive periodic sign-ins, alerting on new inbox rules filtering financial keywords, and requiring out-of-band verification for payroll changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
