logo

Threat Spotlight: Hijacked Routers and Fake Searches Fueling Payroll Heist

ID: 2b53d02b-d82d-5c2d-8f27-db047e77fb82

STIX ID: report--2b53d02b-d82d-5c2d-8f27-db047e77fb82

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2025-05-20

Date Updated: 2026-04-29

...
...

ReliaQuest investigated an active SEO poisoning campaign that targeted employee mobile devices with mobile-optimized phishing sites impersonating corporate login portals to harvest credentials; stolen credentials were used to access SAP SuccessFactors and reroute employee direct deposits. The adversary leveraged Pusher for real-time exfiltration of credentials and residential/mobile proxy networks (including compromised home routers) to mask access, complicating detection and investigation. Recommendations include enforcing MFA and conditional access, using SSO/bookmarks instead of search results, monitoring direct-deposit changes, and employing digital risk protection to detect impersonating domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.