Storm-2755 'Payroll Pirate' Campaign: AiTM Phishing and Workday Account Hijacking Targeting Canadian Employees (CVE-2025-27152) — Threadlinqs Intelligence
As of 2026-05-30, Storm-2755 'Payroll Pirate' Campaign: AiTM Phishing and Workday Account Hijacking Targeting Canadian Employees (CVE-2025-27152) is a high-severity phishing threat attributed to Storm-2755 (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0346 · Severity: HIGH · CVSS: 7.5 · Status: MONITORING · Category: PHISHING
Attribution: Storm-2755 · N/A · FINANCIAL
Microsoft Threat Intelligence is tracking Storm-2755, a financially motivated actor conducting 'payroll pirate' attacks against Canadian employees. The group uses SEO poisoning and malvertising to
Storm-2755 is a financially motivated threat cluster identified by the Microsoft Incident Response (DART) and Microsoft Threat Intelligence teams as the operator behind an active 'payroll pirate' campaign targeting Canadian employees throughout early 2026. The group combines initial credential and token theft with session persistence and targeted HR/payroll reconnaissance to redirect victims' salary payments into attacker-controlled bank accounts, netting direct financial losses for compromised workers and their employers. The campaign follows the operational playbook previously documented in Microsoft's October 2025 reporting on Storm-2657, which targeted U.S. university employees with the same payroll redirection TTP, but Storm-2755 represents a distinct cluster focused geographically on Canadian organizations.
Initial access is achieved through SEO poisoning and malvertising on industry-agnostic search terms such as 'Office 365' and common misspellings like 'Office 265'. The actor-controlled domain bluegraintours[.]com is positioned at the top of search results and serves a high-fidelity clone of the Microsoft 365 sign-in experience. Victims who enter credentials on the page interact with an adversary-in-the-middle (AiTM) framework that transparently proxies the authentication flow to Microsoft Entra ID, harvesting primary credentials alongside post-MFA session cookies and OAuth access tokens. Microsoft observed Entra sign-in logs consistently returning error code 50199 (sign-in interrupt) immediately prior to successful token issuance, a signature indicator of Storm-2755's AiTM phishing kit.
Once a session token is captured, Storm-2755 replays it using a malicious Axios 1.7.9 HTTP client. Axios 1.7.x is affected by CVE-2025-27152, a server-side request forgery / absolute URL handling flaw that the actor weaponizes to proxy Entra authentication flows and relay tokens without re-authentication. Because legacy multi-factor authentication is satisfied at the time the session is minted, the stolen cookie lets the attacker fully bypass MFA from attacker-owned infrastructure. Microsoft observed the session ID remaining unchanged across geographically distant IP address changes, a reliable compromise signal. Non-interactive sign-ins to the OfficeHome application are issued by the attacker approximately every 30 minutes to keep tokens warm, and token renewal activity was concentrated around 05:00 local victim time to evade business-hours anomaly detection.
In the discovery phase, Storm-2755 performs intranet and mailbox searches for keywords including 'payroll', 'HR', 'human', 'resources', 'support', 'info', 'finance', 'account', and 'admin' to map the victim's HR and payroll workflow. To suppress victim awareness of the impending fraud, the actor creates Outlook inbox rules (New-InboxRule) that automatically move any incoming message containing the strings 'direct deposit' or 'bank' to the Conversation History folder or delete them outright, and sets StopProcessingRules so the forged email chains never surface in the Inbox. Storm-2755 then sends spoofed messages with the subject line 'Question about direct deposit' to HR personnel on behalf of the victim, laying groundwork for the banking change.
The impact stage is executed hands-on-keyboard against the victim's Workday tenant. Using the hijacked Microsoft 365 SSO session, the attacker authenticates to Workday and navigates to 'Change My Account' and 'Manage Payment Elections', substituting attacker-controlled bank account and routing numbers on the direct deposit configuration. Because the rogue mailbox rules suppress every confirmation email from Workday and the HR team, the victim receives no notification until the first pay cycle fails to deposit. Although Microsoft's published case work centers on Workday, the same token replay and social-engineering workflow translates cleanly to ADP, UKG Pro, Ceridian Dayforce, and any SaaS payroll platform that accepts Entra ID SSO to
Weaknesses (CWE)
CWE-918, CWE-287, CWE-522, CWE-1021
Target sectors: technology, financial, healthcare, education, government, professional_services, retail, manufacturing
Target regions: Canada, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, CVE-2025-27152, T1583, T1608.006, T1650, T1566.002, T1189, T1557, T1539, T1528, T1187, T1598.003