Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance Emails — Threadlinqs Intelligence
As of 2026-08-07, Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance Emails is a high-severity phishing threat attributed to Storm-2755, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1930 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Storm-2755 · FINANCIAL
A financially motivated adversary-in-the-middle (AitM) phishing campaign tied to Microsoft's Storm-2755 cluster (the 'Payroll Pirates') is hijacking Microsoft 365 sessions via a six-stage redirection
Arctic Wolf Labs documented a new wave of adversary-in-the-middle (AitM) phishing activity attributed to Microsoft's Storm-2755 cluster, publicly known as 'Payroll Pirates,' and overlapping in tradecraft with the related Storm-2657 cluster. Victims receive voicemail-themed phishing emails containing a six-stage redirection chain designed to evade URL-reputation filtering: a Google Meet link redirect, through Google's outbound-link infrastructure, through a Google Ads Campaign Manager /ddm/clk dynamic click tracker, to an Amazon AWS S3-hosted HTML phishing page, proxied to the victim, and finally to a spoofed Microsoft OAuth authorization endpoint. The phishing pages run JavaScript to fingerprint the visiting host and query the api.country[.]is geolocation API, storing the result in a 7-day 'rcfh_country' cookie so that follow-on sign-ins can be routed through a residential proxy exit node in the victim's own country.
Once credentials and MFA codes are captured and silently relayed through the AitM proxy, the threat actor begins signing in from a residential proxy exit node within minutes, then maintains the hijacked session by refreshing it every eight hours from rotating residential-proxy IP addresses while reusing the same SessionID. Centralized automation drives this rotation across many victim tenants simultaneously; sign-ins frequently show implausible client/OS combinations (e.g., Mobile Safari user agents from a Windows 10 host) and non-Edge Outlook clients (Firefox 131.0/151.0, Python Requests). Post-compromise activity is deliberately minimal and 'hands-off': the actor enumerates the Entra ID/Microsoft Graph directory for payroll, HR, finance, and administrative personnel (observed with the axios/1.18.1 user agent), then uses the Graph API MailItemsAccessed 'Bind' operation to collect payroll, invoice, payment, banking, benefits, and internal-document email content. Selective inbox rules are created to move flagged messages to Deleted Items rather than performing conspicuous account changes, limiting opportunities for victim-side detection.
This campaign extends a documented lineage: Storm-2657 was first disclosed by Microsoft and The Hacker News in October 2025 after compromising 11 accounts at three U.S. universities and using them to phish nearly 6,000 accounts across 25 institutions, hijacking Workday profiles to reroute salary direct deposits. In April 2026, Microsoft's DART team investigated a related Storm-2755 wave targeting Canadian employees industry-agnostically via SEO-poisoned/malvertised lookalike sign-in pages, non-interactive token replay via Axios/1.7.9 roughly every 30 minutes, and manual Workday banking-detail changes after suppressing 'direct deposit'/'bank' emails via inbox rules. Security Risk Advisors' June 2026 threat bulletin formalized the AitM-session-hijacking-plus-Graph-reconnaissance pattern across multiple client environments. The August 2026 Arctic Wolf findings represent a distinct new infrastructure/TTP set for the same actor set — the Google Meet/Ads/S3 redirect chain and residential-proxy 8-hour refresh cadence were not present in the earlier Storm-2755/Storm-2657 reporting.
Because the entire attack chain lives in identity and cloud telemetry rather than the endpoint, detection depends on Entra ID sign-in logs (AADSTS90014 'missing nonce' and AADSTS50199 'sign-in interrupt' errors preceding compromise, non-Edge Outlook clients, eight-hour periodic sign-in cadence with a stable SessionID across changing IPs/ASNs) and Microsoft Graph audit telemetry (the ClientAppId 5d661950-3475-41cd-a2c3-d671a3162bc1 paired with APIId c999ed3e-27ae-4cb3-b3a2-46b056af63d3 on MailItemsAccessed Bind events, and cross-tenant clustering of near-simultaneous mailbox access). Recommended hardening includes phishing-resistant MFA (FIDO2/WebAuthn), Conditional Access restricted to managed/compliant devices, and Continuous Access Evaluation to revoke hijacked sessions in near-real time.
Target sectors: health, education, manufacturing, government administration, professional services
Target regions: united states of america, canada, Europe
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583.001, T1583.006, T1592.004, T1566.002, T1204.001, T1557, T1187, T1550.001, T1078.004, T1564.008