Microsoft: Canadian employees targeted in payroll pirate attacks
ID: 91ac1515-8df8-54cf-b9f9-d6bd7f6b3012
STIX ID: report--91ac1515-8df8-54cf-b9f9-d6bd7f6b3012
Feed Name: Bleeping Computer
Storm-2755 is conducting financially motivated payroll-pirate campaigns against Canadian employees by using AiTM phishing pages that capture Microsoft 365 session cookies and OAuth tokens to bypass legacy MFA. After account takeover the actors create hidden inbox rules, search for payroll/HR correspondence, socially engineer HR staff or log into HR platforms like Workday to change direct-deposit details; Microsoft recommends blocking legacy authentication, deploying phishing-resistant MFA, revoking compromised tokens/sessions, and removing malicious inbox rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
