# Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance Emails

> A financially motivated adversary-in-the-middle (AitM) phishing campaign tied to Microsoft's Storm-2755 cluster (the 'Payroll Pirates') is hijacking Microsoft 365 sessions via a six-stage redirection chain and rotating residential proxies, refreshing stolen sessions every eight hours to enumerate and harvest payroll/finance mailboxes. Arctic Wolf Labs observed hundreds of targeted organizations across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe over the past month, building on Storm-2755's April 2026 Canadian campaign and the earlier Storm-2657 US-university 'Payroll Pirate' wave first disclosed in October 2025.

- **Published:** 2026-08-07T00:00:00Z
- **Last reviewed:** 2026-08-09T15:51:00.138Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1930
- **ID:** TL-2026-1930
- **Severity:** HIGH (CVSS 7.7)
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** Storm-2755
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-27152

## Description

Arctic Wolf Labs documented a new wave of adversary-in-the-middle (AitM) phishing activity attributed to Microsoft's Storm-2755 cluster, publicly known as 'Payroll Pirates,' and overlapping in tradecraft with the related Storm-2657 cluster. Victims receive voicemail-themed phishing emails containing a six-stage redirection chain designed to evade URL-reputation filtering: a Google Meet link redirect, through Google's outbound-link infrastructure, through a Google Ads Campaign Manager /ddm/clk dynamic click tracker, to an Amazon AWS S3-hosted HTML phishing page, proxied to the victim, and finally to a spoofed Microsoft OAuth authorization endpoint. The phishing pages run JavaScript to fingerprint the visiting host and query the api.country[.]is geolocation API, storing the result in a 7-day 'rcfh_country' cookie so that follow-on sign-ins can be routed through a residential proxy exit node in the victim's own country.

Once credentials and MFA codes are captured and silently relayed through the AitM proxy, the threat actor begins signing in from a residential proxy exit node within minutes, then maintains the hijacked session by refreshing it every eight hours from rotating residential-proxy IP addresses while reusing the same SessionID. Centralized automation drives this rotation across many victim tenants simultaneously; sign-ins frequently show implausible client/OS combinations (e.g., Mobile Safari user agents from a Windows 10 host) and non-Edge Outlook clients (Firefox 131.0/151.0, Python Requests). Post-compromise activity is deliberately minimal and 'hands-off': the actor enumerates the Entra ID/Microsoft Graph directory for payroll, HR, finance, and administrative personnel (observed with the axios/1.18.1 user agent), then uses the Graph API MailItemsAccessed 'Bind' operation to collect payroll, invoice, payment, banking, benefits, and internal-document email content. Selective inbox rules are created to move flagged messages to Deleted Items rather than performing conspicuous account changes, limiting opportunities for victim-side detection.

This campaign extends a documented lineage: Storm-2657 was first disclosed by Microsoft and The Hacker News in October 2025 after compromising 11 accounts at three U.S. universities and using them to phish nearly 6,000 accounts across 25 institutions, hijacking Workday profiles to reroute salary direct deposits. In April 2026, Microsoft's DART team investigated a related Storm-2755 wave targeting Canadian employees industry-agnostically via SEO-poisoned/malvertised lookalike sign-in pages, non-interactive token replay via Axios/1.7.9 roughly every 30 minutes, and manual Workday banking-detail changes after suppressing 'direct deposit'/'bank' emails via inbox rules. Security Risk Advisors' June 2026 threat bulletin formalized the AitM-session-hijacking-plus-Graph-reconnaissance pattern across multiple client environments. The August 2026 Arctic Wolf findings represent a distinct new infrastructure/TTP set for the same actor set — the Google Meet/Ads/S3 redirect chain and residential-proxy 8-hour refresh cadence were not present in the earlier Storm-2755/Storm-2657 reporting.

Because the entire attack chain lives in identity and cloud telemetry rather than the endpoint, detection depends on Entra ID sign-in logs (AADSTS90014 'missing nonce' and AADSTS50199 'sign-in interrupt' errors preceding compromise, non-Edge Outlook clients, eight-hour periodic sign-in cadence with a stable SessionID across changing IPs/ASNs) and Microsoft Graph audit telemetry (the ClientAppId 5d661950-3475-41cd-a2c3-d671a3162bc1 paired with APIId c999ed3e-27ae-4cb3-b3a2-46b056af63d3 on MailItemsAccessed Bind events, and cross-tenant clustering of near-simultaneous mailbox access). Recommended hardening includes phishing-resistant MFA (FIDO2/WebAuthn), Conditional Access restricted to managed/compliant devices, and Continuous Access Evaluation to revoke hijacked sessions in near-real time.

## MITRE ATT&CK

- T1583.001 Domains
- T1583.006 Web Services
- T1592.004 Client Configurations
- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1557 Adversary-in-the-Middle
- T1187 Forced Authentication
- T1550.001 Application Access Token
- T1078.004 Cloud Accounts
- T1564.008 Email Hiding Rules
- T1684.001 Impersonation
- T1087.004 Cloud Account
- T1526 Cloud Service Discovery
- T1538 Cloud Service Dashboard
- T1114.002 Remote Email Collection
- T1608.005 Stage Capabilities
- T1583.008 Acquire Infrastructure
- T1556 Modify Authentication Process
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1550.004 Use Alternate Authentication Material
- T1036.005 Masquerading
- T1090.002 Proxy

## Sources

- [Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails](https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html)
- [Payroll Pirates: Strange New Tides in Business Email Compromise](https://arcticwolf.com/resources/blog/payroll-pirates-strange-new-tides-in-business-email-compromise/)
- [Investigating Storm-2755: "Payroll pirate" attacks targeting Canadian employees](https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/)
- [Microsoft Warns of 'Payroll Pirates' Hijacking HR SaaS Accounts to Steal Salaries](https://thehackernews.com/2025/10/microsoft-warns-of-payroll-pirates.html)
- [The Payroll Pirate Campaign Leverages AiTM Session Hijacking to Target HR Departments](https://securityonline.info/payroll-pirate-campaign-aitm-hijacking/)
- ["Payroll Pirate" Campaign: AiTM Session Hijacking and Microsoft Graph Reconnaissance Across Multiple Client Environments](https://exchange.xforce.ibmcloud.com/osint/guid:0b4151587274492894c2d5d8d615462e)
- [Hackers Use Microsoft Graph Reconnaissance to Target Payroll and HR Employees](https://cybersecuritynews.com/hackers-use-microsoft-graph-reconnaissance/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1930
