AiTM Phishing Hijacks Microsoft 365 Sessions, Targets Payroll Emails
Key Takeaways A new phishing campaign, dubbed “Payroll Pirates,” is actively hijacking Microsoft 365 sessions using sophisticated Adversary-in-the-Middle (AiTM) techniques. The attackers...
Key Takeaways
- A new phishing campaign, dubbed “Payroll Pirates,” is actively hijacking Microsoft 365 sessions using sophisticated Adversary-in-the-Middle (AiTM) techniques.
- The attackers bypass multi-factor authentication (MFA) by capturing session tokens after users complete their legitimate sign-in process.
- The primary objective is financial fraud, achieved by compromising accounts, identifying finance-related personnel, and gathering information to facilitate payroll and direct-deposit changes.
- Organizations across healthcare, education, manufacturing, government, and professional services in North America and Europe have been affected.
Payroll Pirates Leverage AiTM Phishing for Microsoft 365 Session Hijacks
A malicious campaign identified as “Payroll Pirates” is actively employing advanced phishing tactics to compromise Microsoft 365 accounts, bypass multi-factor authentication (MFA), and target payroll-related information for financial gain. This sophisticated operation transforms seemingly innocuous voicemail notifications into a direct pathway for financial fraud, according to a recent report by Arctic Wolf.
Table Of Content
The attackers initiate the scheme by sending phishing emails designed to mimic automated voicemail alerts. These messages entice recipients to click on a link to access a “voicemail portal.” This click, however, leads through a series of redirect services before ultimately landing on a fake Microsoft sign-in page. This page acts as an Adversary-in-the-Middle (AiTM) proxy, relaying the genuine Microsoft login process while simultaneously capturing authentication codes and session tokens, even after the victim successfully completes MFA.
Arctic Wolf’s analysis revealed widespread activity across diverse sectors, including healthcare, education, manufacturing, government, and professional services organizations throughout North America and Europe. In July alone, hundreds of organizations received these malicious emails, with intrusions detected in various IT environments, as detailed in their comprehensive report. This operation bears resemblance to Microsoft’s Storm-2755 threat group, also known as Payroll Pirates. Instead of immediate fraudulent actions, the attackers prioritize maintaining access, identifying key finance personnel, and accumulating information for future payroll manipulation.
The AiTM Phishing Methodology
The initial phishing email is crafted to appear legitimate, featuring a Microsoft logo, fabricated caller information, and a subject line structured as “[Organization] :ATTN: Review messages. Ref id: [random string].” Clicking on the embedded link initiates a multi-stage redirect chain, cleverly utilizing legitimate services like Google Meet, Google advertising links, and Amazon S3 hosting. This technique makes it significantly harder for conventional reputation filters to detect the malicious destination.
Upon reaching the final phishing site, an AiTM proxy intercepts the connection between the victim and Microsoft. This proxy meticulously forwards authentic Microsoft authentication pages in real-time. As the victim completes their login credentials and multi-factor authentication, the proxy captures the authorization code and session material. This session hijacking capability renders simple password resets ineffective as a standalone remediation strategy.
The phishing kit also incorporates advanced fingerprinting techniques, analyzing browser details, screen settings, language preferences, geographical location, and indicators of automation before redirecting users. Subsequently, the attackers appear to leverage residential proxy infrastructure strategically located near the victim’s country. This makes subsequent malicious sign-ins appear to originate from ordinary home or mobile connections, further evading detection. This relay approach highlights why traditional MFA alone struggles to mitigate sophisticated AiTM phishing attacks targeting cloud accounts.
Soon after a successful compromise, suspicious sign-ins to OfficeHome accounts can commence. Arctic Wolf observed unusual device and browser combinations, such as mobile browsers being reported on Windows 10, and in some instances, an “errorCode: 90014” during authentication attempts. While not universally present, the occurrence of this error alongside other anomalous signals provides valuable clues for forensic investigations.
Exploiting Compromised Sessions for Financial Fraud
Approximately 11 to 24 hours after gaining initial access, the attackers begin to refresh the compromised sessions roughly every eight hours. This activity originates from constantly changing residential IP addresses. The persistence of the same SessionID despite shifts in IP address, network, and geographical location strongly suggests automated, centrally managed access rather than legitimate user activity across different networks.
The threat actors then leverage Microsoft Graph to conduct reconnaissance, searching for individuals in payroll, HR, finance, and administrative roles. Following this, they access mailboxes containing sensitive information related to invoices, payments, banking details, employee benefits, and internal documents. This strategic information gathering aligns with known tactics where mailbox intelligence is used to target salary or direct-deposit processes for fraudulent purposes.
Interestingly, most observed incidents did not involve immediate password changes, the registration of new devices, the setup of email forwarding rules, or broad outbound phishing campaigns. This operational restraint is a deliberate tactic to minimize detection and avoid triggering security alerts. In a smaller subset of cases, however, the attackers established mailbox rules to automatically move incoming messages to the “Deleted Items” folder and mark them as read. This maneuver effectively conceals responses while the criminals pursue financial requests.
What You Should Do
- Correlate Logs: Do not examine individual sign-ins in isolation. Instead, correlate identity, session, and mailbox logs to identify patterns of suspicious activity.
- Investigate Anomalies: Look for specific indicators such as Outlook activity originating from unusual user agents (e.g., Firefox or Python Requests), recurring eight-hour access intervals with a consistent SessionID but changing IP addresses, Microsoft Graph searches for finance-related roles, and unusual MailItemsAccessed events.
- Verify Bank Detail Changes: Implement a robust, independent verification process for any requests to change bank details for payroll or vendor payments.
- Immediate Response to Compromise: If a compromise is suspected, immediately revoke all active sessions, reset compromised user credentials, and re-register multi-factor authentication.
- Thorough Audit: Review payroll and HR system activity for the entire potential exposure period, paying close attention to direct-deposit changes. Additionally, check audit logs to determine which messages were accessed and search for similar access patterns across other user accounts.
- Implement Phishing-Resistant MFA: For long-term protection, deploy phishing-resistant sign-in methods such as FIDO2 security keys.
- Managed Device Access: Enforce access rules that limit Microsoft 365 access to managed devices only.
- Continuous Access Evaluation (CAE): Enable CAE to ensure real-time enforcement of security policies and immediate revocation of compromised sessions.
- Retain Non-Interactive Sign-in Logs: Ensure comprehensive retention of non-interactive sign-in logs, as periodic session refreshes by attackers might otherwise go unnoticed.
- Employee Training: Conduct regular cybersecurity awareness training for all staff, specifically instructing them to report any unexpected voicemail notifications or suspicious links before clicking on them.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.