Storm-2755 'Payroll Pirate' Campaign: AiTM Phishing and Workday Account Hijacking Targeting Canadian Employees (CVE-2025-27152)

Storm-2755 'Payroll Pirate' Campaign (TL-2026-0346), also tracked as Payroll Pirate (Canadian Campaign), is a high-severity phishing campaign scored CVSS 7.5, first published 2026-04-10. It is attributed to Storm-2755 with medium confidence, affects Microsoft Microsoft 365 / Entra ID, references 1 CVE (CVE-2025-27152), maps to 25 MITRE ATT&CK techniques (T1071.001, T1078.004, T1087), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-0346

Threat ID
TL-2026-0346
Also known as
Payroll Pirate (Canadian Campaign), Storm-2755 Payroll Fraud
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Status
MONITORING
Category
PHISHING
First published
2026-04-10
Last reviewed
2026-04-10
Attribution
Storm-2755
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, financial, healthcare, education, government, professional_services, retail, manufacturing
Target regions
Canada, North America
Detection rules
9
Indicators of compromise
18

Malware and tooling in Storm-2755 'Payroll Pirate' Campaign

Malware and tooling: AiTM phishing kit with Axios 1.7.9 relay backend

Microsoft Threat Intelligence is tracking Storm-2755, a financially motivated actor conducting 'payroll pirate' attacks against Canadian employees. The group uses SEO poisoning and malvertising to lure victims to an adversary-in-the-middle (AiTM) phishing site at bluegraintours[.]com, captures Microsoft 365 session tokens via a malicious Axios 1.7.9 client (CVE-2025-27152), creates inbox rules to hide HR correspondence, then hijacks Workday sessions to rewrite direct deposit banking details and redirect salary payments to attacker-controlled bank accounts.

How Storm-2755 'Payroll Pirate' Campaign works

Storm-2755 is a financially motivated threat cluster identified by the Microsoft Incident Response (DART) and Microsoft Threat Intelligence teams as the operator behind an active 'payroll pirate' campaign targeting Canadian employees throughout early 2026. The group combines initial credential and token theft with session persistence and targeted HR/payroll reconnaissance to redirect victims' salary payments into attacker-controlled bank accounts, netting direct financial losses for compromised workers and their employers. The campaign follows the operational playbook previously documented in Microsoft's October 2025 reporting on Storm-2657, which targeted U.S. university employees with the same payroll redirection TTP, but Storm-2755 represents a distinct cluster focused geographically on Canadian organizations.

Initial access is achieved through SEO poisoning and malvertising on industry-agnostic search terms such as 'Office 365' and common misspellings like 'Office 265'. The actor-controlled domain bluegraintours[.]com is positioned at the top of search results and serves a high-fidelity clone of the Microsoft 365 sign-in experience. Victims who enter credentials on the page interact with an adversary-in-the-middle (AiTM) framework that transparently proxies the authentication flow to Microsoft Entra ID, harvesting primary credentials alongside post-MFA session cookies and OAuth access tokens. Microsoft observed Entra sign-in logs consistently returning error code 50199 (sign-in interrupt) immediately prior to successful token issuance, a signature indicator of Storm-2755's AiTM phishing kit.

Once a session token is captured, Storm-2755 replays it using a malicious Axios 1.7.9 HTTP client. Axios 1.7.x is affected by CVE-2025-27152, a server-side request forgery / absolute URL handling flaw that the actor weaponizes to proxy Entra authentication flows and relay tokens without re-authentication. Because legacy multi-factor authentication is satisfied at the time the session is minted, the stolen cookie lets the attacker fully bypass MFA from attacker-owned infrastructure. Microsoft observed the session ID remaining unchanged across geographically distant IP address changes, a reliable compromise signal. Non-interactive sign-ins to the OfficeHome application are issued by the attacker approximately every 30 minutes to keep tokens warm, and token renewal activity was concentrated around 05:00 local victim time to evade business-hours anomaly detection.

In the discovery phase, Storm-2755 performs intranet and mailbox searches for keywords including 'payroll', 'HR', 'human', 'resources', 'support', 'info', 'finance', 'account', and 'admin' to map the victim's HR and payroll workflow. To suppress victim awareness of the impending fraud, the actor creates Outlook inbox rules (New-InboxRule) that automatically move any incoming message containing the strings 'direct deposit' or 'bank' to the Conversation History folder or delete them outright, and sets StopProcessingRules so the forged email chains never surface in the Inbox. Storm-2755 then sends spoofed messages with the subject line 'Question about direct deposit' to HR personnel on behalf of the victim, laying groundwork for the banking change.

The impact stage is executed hands-on-keyboard against the victim's Workday tenant. Using the hijacked Microsoft 365 SSO session, the attacker authenticates to Workday and navigates to 'Change My Account' and 'Manage Payment Elections', substituting attacker-controlled bank account and routing numbers on the direct deposit configuration. Because the rogue mailbox rules suppress every confirmation email from Workday and the HR team, the victim receives no notification until the first pay cycle fails to deposit. Although Microsoft's published case work centers on Workday, the same token replay and social-engineering workflow translates cleanly to ADP, UKG Pro, Ceridian Dayforce, and any SaaS payroll platform that accepts Entra ID SSO tokens.

Microsoft's defensive guidance centers on phishing-resistant MFA (FIDO2 / Windows Hello for Business), Continuous Access Evaluation (CAE), Conditional Access policies that bind sessions to compliant Intune-managed devices, blocking legacy authentication, and alerting on New-InboxRule / Set-InboxRule activity that filters on payroll keywords. Payroll and HR teams should immediately implement out-of-band verification of all direct deposit change requests and audit the last 90 days of Workday 'Manage Payment Elections' events for anomalies. Defenders should hunt for Axios/1.7.9 user-agent strings in Entra sign-in logs, Entra error code 50199 patterns, and any inbound connection to bluegraintours[.]com at the DNS and web proxy layer.

MITRE ATT&CK techniques used in TL-2026-0346

command-and-control

T1071.001 Web Protocols; T1102 Web Service

defense-evasion

T1078.004 Cloud Accounts; T1564.008 Email Hiding Rules

discovery

T1087 Account Discovery

persistence

T1098 Account Manipulation; T1098.002 Additional Email Delegate Permissions; T1137.005 Outlook Rules

collection

T1114 Email Collection; T1114.002 Remote Email Collection

credential-access

T1187 Forced Authentication; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

initial-access

T1189 Drive-by Compromise; T1566.002 Spearphishing Link

lateral-movement

T1550.001 Application Access Token; T1550.004 Web Session Cookie

impact

T1565.001 Stored Data Manipulation; T1657 Financial Theft

exfiltration

T1567 Exfiltration Over Web Service

resource-development

T1583 Acquire Infrastructure; T1608.006 SEO Poisoning; T1650 Acquire Access

reconnaissance

T1598.003 Spearphishing Link

Affected products and versions in Storm-2755 'Payroll Pirate' Campaign

  • Microsoft — Microsoft 365 / Entra ID
    Vulnerable versions: all tenants without phishing-resistant MFA
    Fixed in: tenants enforcing FIDO2 + CAE + Intune compliance
  • Workday — Workday HCM (Payment Elections)
    Vulnerable versions: all tenants allowing SSO-based payment election changes without step-up auth
    Fixed in: tenants requiring step-up MFA for banking changes
  • Axios — axios
    Vulnerable versions: 1.0.0 through 1.8.1
    Fixed in: 1.8.2
  • ADP — ADP Workforce Now / Run
    Vulnerable versions: all tenants accepting SSO without step-up for banking changes
  • UKG — UKG Pro / Ready
    Vulnerable versions: all tenants accepting SSO without step-up for banking changes

Remediation for Storm-2755 'Payroll Pirate' Campaign

Patches

  • Upgrade Axios to 1.8.2 or later to remediate CVE-2025-27152
  • Apply Microsoft Entra ID token protection preview features where available

Immediate actions

  • Block bluegraintours[.]com and any associated subdomains at DNS, web proxy, and email gateway
  • Revoke all sessions and refresh tokens for any user who authenticated via the malicious domain or shows Entra error 50199 followed by successful sign-in
  • Remove Outlook inbox rules that filter on 'direct deposit', 'bank', or 'payroll' keywords with MoveToFolder or DeleteMessage actions
  • Contact affected employees and payroll teams out-of-band to verify every direct deposit change processed in the last 90 days
  • Freeze and audit all Workday 'Manage Payment Elections' changes until the intrusion is scoped

Workarounds

  • Restrict Workday and payroll SaaS bank account changes to managed, on-premises-only network segments via Conditional Access named locations
  • Enforce HR workflow requiring a second approver for any direct deposit routing/account number modification

Longer-term hardening

  • Deploy phishing-resistant MFA using FIDO2 security keys or Windows Hello for Business
  • Enable Continuous Access Evaluation (CAE) in Microsoft Entra ID to invalidate stolen tokens on risk events
  • Implement Conditional Access policies requiring Intune-compliant devices for Workday, ADP, and other payroll SaaS access
  • Block all legacy authentication protocols (IMAP, POP3, SMTP AUTH, basic authentication)
  • Require out-of-band (phone callback) confirmation for all direct deposit changes initiated through HR self-service portals
  • Shorten Microsoft 365 and payroll SaaS session token lifetimes and enforce token binding where supported
  • Deploy Microsoft Defender for Cloud Apps policies alerting on anomalous Workday 'Change My Account' events

CVEs associated with Storm-2755 'Payroll Pirate' Campaign

CVE-2025-27152

Weaknesses (CWE) in Storm-2755 'Payroll Pirate' Campaign

CWE-918, CWE-287, CWE-522, CWE-1021

Timeline of Storm-2755 'Payroll Pirate' Campaign

  • CVE-2025-27152 disclosed for Axios: SSRF / absolute URL handling flaw in HTTP client later abused by Storm-2755 for token relay.
  • Microsoft publishes Storm-2657 report on payroll pirate attacks targeting U.S. university employees via Workday direct deposit manipulation - the operational template for Storm-2755.
  • Storm-2755 registers and stands up the phishing domain bluegraintours[.]com, hosting an AiTM Microsoft 365 sign-in clone.
  • Malvertising and SEO poisoning on 'Office 365' and 'Office 265' search terms begins driving Canadian victims to bluegraintours[.]com.
  • Microsoft DART observes first Canadian employee credential and token theft events tied to Storm-2755 infrastructure and the Axios 1.7.9 user-agent.
  • Storm-2755 escalates to hands-on-keyboard Workday Payment Elections manipulation, redirecting direct deposits to attacker-controlled bank accounts.
  • Investigators confirm a consistent inbox rule TTP: New-InboxRule filtering 'direct deposit' or 'bank' with MoveToFolder to Conversation History and StopProcessingRules enabled.
  • Microsoft Threat Intelligence publishes the 'Investigating Storm-2755: Payroll pirate attacks targeting Canadian employees' blog post with IOCs, detection queries, and mitigation guidance.
  • Threadlinqs Intelligence assigns TL-2026-0346 and publishes consolidated research, detections, and simulation guidance.
  • BleepingComputer and other outlets amplify the disclosure; Canadian employers begin mass session revocation and HR direct-deposit audits.
  • As of 2026-05-29, Storm-2755's payroll-pirate campaign remains a live concern: Microsoft (disclosed Apr 9, 2026) has run disruption/tenant takedowns but reports no arrests or full dismantlement, and its AiTM/SEO-poisoning/Workday SSO session-hijacking playbook is easily re-tooled. CVE-2025-27152 is patched (axios 1.8.2) and not in CISA KEV, but it runs on attacker infrastructure, so the patch does not neutralize the threat.

Sources cited for Storm-2755 'Payroll Pirate' Campaign

Threats related to Storm-2755 'Payroll Pirate' Campaign

Detection coverage for TL-2026-0346

As of 2026-04-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0346 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats