Threat reportPhishingTL-2026-1930
Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance Emails
Microsoft 365 AitM Phishing Campaign Hijacks Sessions via (TL-2026-1930), also tracked as Payroll Pirates, is a high-severity phishing campaign scored CVSS 7.7, first published 2026-08-07 and last reviewed 2026-08-09. It is attributed to Storm-2755 with medium confidence, affects Microsoft Microsoft 365 / Entra ID, references 1 CVE (CVE-2025-27152), maps to 23 MITRE ATT&CK techniques (T1036.005, T1078.004, T1087.004), and is covered by 9 detection rules and 30 indicators of compromise.
- CVSS
- 7.7/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 23MITRE ATT&CK
- Actors
- 1Storm-2755
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-1930
- Threat ID
- TL-2026-1930
- Also known as
- Payroll Pirates
- Severity
- HIGH
- CVSS
- 7.7
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- Storm-2755
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- health, education, manufacturing, government administration, professional services
- Target regions
- united states of america, canada, Europe
- Detection rules
- 9
- Indicators of compromise
- 30
- Updates
- 2026-08-09 · revalidated 1× · latest source
Malware and tooling in Microsoft 365 AitM Phishing Campaign Hijacks Sessions via
Malware and tooling: Firefox 131.0, Firefox 151.0, Python Requests, axios/1.18.1, axios/1.7.9
How Microsoft 365 AitM Phishing Campaign Hijacks Sessions via works
A financially motivated adversary-in-the-middle (AitM) phishing campaign tied to Microsoft's Storm-2755 cluster (the 'Payroll Pirates') is hijacking Microsoft 365 sessions via a six-stage redirection chain and rotating residential proxies, refreshing stolen sessions every eight hours to enumerate and harvest payroll/finance mailboxes. Arctic Wolf Labs observed hundreds of targeted organizations across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe over the past month, building on Storm-2755's April 2026 Canadian campaign and the earlier Storm-2657 US-university 'Payroll Pirate' wave first disclosed in October 2025.
Arctic Wolf Labs documented a new wave of adversary-in-the-middle (AitM) phishing activity attributed to Microsoft's Storm-2755 cluster, publicly known as 'Payroll Pirates,' and overlapping in tradecraft with the related Storm-2657 cluster. Victims receive voicemail-themed phishing emails containing a six-stage redirection chain designed to evade URL-reputation filtering: a Google Meet link redirect, through Google's outbound-link infrastructure, through a Google Ads Campaign Manager /ddm/clk dynamic click tracker, to an Amazon AWS S3-hosted HTML phishing page, proxied to the victim, and finally to a spoofed Microsoft OAuth authorization endpoint. The phishing pages run JavaScript to fingerprint the visiting host and query the api.country[.]is geolocation API, storing the result in a 7-day 'rcfh_country' cookie so that follow-on sign-ins can be routed through a residential proxy exit node in the victim's own country.
Once credentials and MFA codes are captured and silently relayed through the AitM proxy, the threat actor begins signing in from a residential proxy exit node within minutes, then maintains the hijacked session by refreshing it every eight hours from rotating residential-proxy IP addresses while reusing the same SessionID. Centralized automation drives this rotation across many victim tenants simultaneously; sign-ins frequently show implausible client/OS combinations (e.g., Mobile Safari user agents from a Windows 10 host) and non-Edge Outlook clients (Firefox 131.0/151.0, Python Requests). Post-compromise activity is deliberately minimal and 'hands-off': the actor enumerates the Entra ID/Microsoft Graph directory for payroll, HR, finance, and administrative personnel (observed with the axios/1.18.1 user agent), then uses the Graph API MailItemsAccessed 'Bind' operation to collect payroll, invoice, payment, banking, benefits, and internal-document email content. Selective inbox rules are created to move flagged messages to Deleted Items rather than performing conspicuous account changes, limiting opportunities for victim-side detection.
This campaign extends a documented lineage: Storm-2657 was first disclosed by Microsoft and The Hacker News in October 2025 after compromising 11 accounts at three U.S. universities and using them to phish nearly 6,000 accounts across 25 institutions, hijacking Workday profiles to reroute salary direct deposits. In April 2026, Microsoft's DART team investigated a related Storm-2755 wave targeting Canadian employees industry-agnostically via SEO-poisoned/malvertised lookalike sign-in pages, non-interactive token replay via Axios/1.7.9 roughly every 30 minutes, and manual Workday banking-detail changes after suppressing 'direct deposit'/'bank' emails via inbox rules. Security Risk Advisors' June 2026 threat bulletin formalized the AitM-session-hijacking-plus-Graph-reconnaissance pattern across multiple client environments. The August 2026 Arctic Wolf findings represent a distinct new infrastructure/TTP set for the same actor set — the Google Meet/Ads/S3 redirect chain and residential-proxy 8-hour refresh cadence were not present in the earlier Storm-2755/Storm-2657 reporting.
Because the entire attack chain lives in identity and cloud telemetry rather than the endpoint, detection depends on Entra ID sign-in logs (AADSTS90014 'missing nonce' and AADSTS50199 'sign-in interrupt' errors preceding compromise, non-Edge Outlook clients, eight-hour periodic sign-in cadence with a stable SessionID across changing IPs/ASNs) and Microsoft Graph audit telemetry (the ClientAppId 5d661950-3475-41cd-a2c3-d671a3162bc1 paired with APIId c999ed3e-27ae-4cb3-b3a2-46b056af63d3 on MailItemsAccessed Bind events, and cross-tenant clustering of near-simultaneous mailbox access). Recommended hardening includes phishing-resistant MFA (FIDO2/WebAuthn), Conditional Access restricted to managed/compliant devices, and Continuous Access Evaluation to revoke hijacked sessions in near-real time.
MITRE ATT&CK techniques used in TL-2026-1930
Defense Evasion
T1036.005 Masquerading; T1550.004 Use Alternate Authentication Material; T1564.008 Email Hiding Rules
Persistence
Discovery
T1087.004 Cloud Account; T1526 Cloud Service Discovery; T1538 Cloud Service Dashboard
Command and Control
Collection
T1114.002 Remote Email Collection
Credential Access
T1187 Forced Authentication; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1556 Modify Authentication Process; T1557 Adversary-in-the-Middle
Execution
lateral-movement
T1550.001 Application Access Token
Initial Access
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1583.008 Acquire Infrastructure; T1608.005 Stage Capabilities
Reconnaissance
T1592.004 Client Configurations
stealth
Affected products and versions in Microsoft 365 AitM Phishing Campaign Hijacks Sessions via
- Microsoft — Microsoft 365 / Entra ID
Vulnerable versions: Tenants without phishing-resistant MFA (FIDO2/WebAuthn) or Continuous Access Evaluation enforced
Fixed in: Tenants enforcing FIDO2/WebAuthn MFA, Conditional Access for managed devices, and Continuous Access Evaluation - Workday — Workday HR/Payroll SaaS
Vulnerable versions: Tenants relying solely on M365 SSO without secondary verification for direct-deposit/banking-detail changes
Fixed in: N/A - process-control gap rather than a software vulnerability
Remediation for Microsoft 365 AitM Phishing Campaign Hijacks Sessions via
Immediate actions
- Revoke all active Microsoft 365/Entra ID sessions and refresh tokens for any account showing eight-hour periodic sign-ins from rotating residential-proxy IPs with a consistent SessionID
- Force credential rotation and MFA re-registration for affected accounts
- Audit and remove inbox rules that move messages containing 'direct deposit', 'bank', 'payroll', or 'invoice' to hidden folders or Deleted Items
- Review Workday/HR-SaaS direct-deposit and banking-detail change logs for the affected user population and revert unauthorized changes
Workarounds
- Block or alert on outbound requests to api.country[.]is and other IP-geolocation lookup services occurring within authenticated M365 sessions
- Add Conditional Access named-location/sign-in risk policies to flag authentications from known residential-proxy ASN ranges
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2/WebAuthn or Windows Hello for Business) tenant-wide, prioritizing payroll, HR, and finance roles
- Enable Continuous Access Evaluation (CAE) and Conditional Access policies restricting sign-in to managed/compliant devices
- Hunt Entra ID sign-in logs for AADSTS90014/AADSTS50199 error codes preceding anomalous authentications and for implausible client/OS combinations (e.g., Mobile Safari UA on Windows 10)
- Monitor Microsoft Graph MailItemsAccessed telemetry for the documented ClientAppId/APIId pairing associated with automated mailbox-collection tooling
CVEs associated with Microsoft 365 AitM Phishing Campaign Hijacks Sessions via
Weaknesses (CWE) in Microsoft 365 AitM Phishing Campaign Hijacks Sessions via
Timeline of Microsoft 365 AitM Phishing Campaign Hijacks Sessions via
- GitHub Security Advisory GHSA-jr5f-v2jv-69x6 (CVE-2025-27152) discloses an SSRF/credential-leakage flaw in axios versions before 1.8.2, later observed weaponized in the Storm-2755 token-relay backend.
- Storm-2657 achieves its earliest documented account compromises at three U.S. universities, the starting point of the 'Payroll Pirates' cluster later linked to this campaign.
- Microsoft and The Hacker News publicly disclose the Storm-2657 'Payroll Pirates' campaign: 11 compromised accounts at 3 universities used to phish nearly 6,000 accounts across 25 institutions, with hijacked Workday profiles rerouting salary payments.
- Microsoft's DART team publishes analysis of Storm-2755 'payroll pirate' attacks targeting Canadian employees industry-agnostically, using SEO-poisoned/malvertised sign-in pages, AADSTS50199-preceded token theft, and Axios/1.7.9 non-interactive token replay roughly every 30 minutes.
- Arctic Wolf Labs observes an updated axios/1.18.1 user-agent tied to continued Microsoft Graph and sign-in reconnaissance activity, indicating the actor's token-relay tooling was upgraded.
- Security Risk Advisors publishes threat bulletin TB20260611-Payroll-Pirates, documenting AiTM session hijacking plus Microsoft Graph reconnaissance (payroll/HR/finance keyword enumeration) across multiple client environments and formalizing the Storm-2755/Storm-2657 TTP overlap.
- Arctic Wolf Labs begins observing hundreds of organizations targeted in a new wave using a six-stage Google Meet/Google Ads/AWS S3 redirection chain and residential-proxy sessions refreshed every eight hours — infrastructure and cadence not present in the earlier Storm-2755/Storm-2657 reporting.
- Arctic Wolf Labs publishes 'Payroll Pirates: Strange New Tides in Business Email Compromise,' detailing the AiTM infrastructure, MailItemsAccessed indicators, and detection guidance.
- Wiz Threat Research and The Hacker News publish coverage of the Microsoft 365 AiTM campaign, consolidating the redirect-chain and Microsoft Graph enumeration findings for defenders.
- Arctic Wolf Labs' findings are published via The Hacker News, confirming successful intrusions harvesting payroll and finance mailbox content across healthcare, education, manufacturing, government, and professional-services organizations in the U.S., Canada, and Europe.
Update history for TL-2026-1930
- 2026-08-09 — Payroll Pirates (Storm-2755): Voicemail-Lure AiTM Phishing Hijacks Microsoft 365 Sessions and Harvests Payroll/Finance Mailboxes (CVE-2025-27152): What changed No severity/exploitability/status escalation (both reports: HIGH/ACTIVE/ACTIVE). New: a concrete CVSS 4.0 score of 7.7 is now available (previously null), tied to the newly identified CVE-2025-27152 in the actor's axios token-r
Sources cited for Microsoft 365 AitM Phishing Campaign Hijacks Sessions via
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
- Payroll Pirates: Strange New Tides in Business Email Compromise
- Investigating Storm-2755: "Payroll pirate" attacks targeting Canadian employees
- Microsoft Warns of 'Payroll Pirates' Hijacking HR SaaS Accounts to Steal Salaries
- The Payroll Pirate Campaign Leverages AiTM Session Hijacking to Target HR Departments
- "Payroll Pirate" Campaign: AiTM Session Hijacking and Microsoft Graph Reconnaissance Across Multiple Client Environments
- Hackers Use Microsoft Graph Reconnaissance to Target Payroll and HR Employees
Detection coverage for TL-2026-1930
As of 2026-08-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1930 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.