Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise — Threadlinqs Intelligence
As of 2026-08-10, Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise is a high-severity phishing threat attributed to Storm-2755, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 13 indicators of compromise.
Threat ID: TL-2026-1970 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Storm-2755 · FINANCIAL
A widespread, financially-motivated campaign overlapping with Microsoft's Storm-2755 ("Payroll Pirates") activity cluster uses voicemail-themed and SEO-poisoned lures to route Microsoft 365 users
Arctic Wolf researchers are tracking a widespread, active Microsoft 365 account-compromise campaign that shares significant tactical overlap with the "Payroll Pirates" activity cluster Microsoft tracks as Storm-2755, first documented publicly by Microsoft's Security Blog on 2026-04-09 against Canadian organizations and now observed more broadly across the U.S., Canada, and Europe.
Victims receive voicemail-themed phishing emails styled as automated call notifications with Microsoft branding and an "OPEN [Organization] VOICEMAIL PORTAL" call to action, with subject lines following the pattern '[Organization] :ATTN: Review messages. Ref id: [random string]'. Clicking the link routes the victim through a multi-stage redirect chain built entirely from abused legitimate infrastructure: a Google Meet link-redirect URL, Google's outbound-link infrastructure, a Google Ads Campaign Manager /ddm/clk dynamic click tracker, and an Amazon S3-hosted landing page, before finally reaching an attacker-registered adversary-in-the-middle (AiTM) domain. Separately, Microsoft's Storm-2755 reporting describes SEO poisoning and malvertising that ranked the actor-controlled domain bluegraintours[.]com at the top of search results for queries like "Office 365" and common misspellings such as "Office 265", driving victims directly to a spoofed Microsoft 365 sign-in page.
The AiTM infrastructure is newly registered (domains observed less than 10 days old at time of use) and hosted on Hostinger, serving over HTTP/2 with response headers 'server: openresty/1.31.1.1' and 'x-powered-by: Express' at the root, and 'x-powered-by: PHP/8.2.32' on a fingerprinting endpoint at path '/st_58200519/class_identifier.php'. That endpoint collects a browser/device fingerprint (navigator properties, screen dimensions, language, timezone, WebGL vendor/renderer, cookie support) and queries api.country.is for geolocation, storing the result in a 7-day 'rcfh_country' cookie, before serving a reverse-proxied copy of the genuine Microsoft authentication flow. Because the kit proxies the real Microsoft login in real time rather than presenting a static credential-harvesting page, it captures session cookies and OAuth access/refresh tokens as the victim completes an otherwise normal sign-in, including MFA — rendering non-phishing-resistant MFA insufficient. A missing OAuth nonce parameter in the AiTM-initiated flow produces the rare Microsoft Entra sign-in error 90014, and Entra error 50199 has been observed immediately preceding successful token replay; both are high-fidelity indicators when paired with residential-proxy source traffic. Microsoft's Storm-2755 reporting separately documents an Axios/1.7.9 HTTP client used to replay stolen tokens roughly every 30 minutes, keeping sessions alive for up to approximately 30 days until refresh-token expiration.
Post-compromise sign-in activity shows a distinctive pattern: an initial burst of sign-ins from multiple residential-proxy IP addresses within seconds of compromise, often reporting implausible OS/browser combinations (e.g., Mobile Safari reported on Windows 10); recurring "maintenance" sign-ins roughly every 8 hours (11-24 hours after the initial burst) from rotating residential-proxy addresses commonly associated with an "anyIP"-style network; and a single Entra SessionID persisting unchanged across many different source IP addresses, ASNs, and geographic locations. The client consistently claims to be Microsoft Outlook while the actual user-agent string is anomalous — Firefox 131.0, Firefox 151.0, or Python Requests — rather than a genuine Outlook/Edge client.
Once inside a tenant, the actor queries Microsoft Graph (GET https://graph.microsoft.com/v1.0/users with role/department filters for payroll, HR, finance, and administrative terms; GET https://graph.microsoft.com/v1.0/users?$top=999 for broad enumeration; and GET https://graph.microsoft.com/v1.0/me) using the user-agent 'axios/1.18.1', triggering the Microsoft Defe
Target sectors: health, education, manufacturing, government administration, professionalservices
Target regions: North America, Europe, united states of america, canada
Timeline
- Microsoft Security Blog publishes the first public analysis of Storm-2755 "payroll pirate" attacks, documenting SEO-poisoned/malvertised bluegraintours[.]com AiTM sign-in pages, Axios token-replay, inbox-rule concealment of direct-deposit correspondence, and social-engineering of HR/Workday to redirect Canadian employees' salaries.
- Arctic Wolf observes a broader wave of the AiTM/Microsoft Graph reconnaissance activity throughout July 2026, expanding beyond the originally reported Canadian scope to hundreds of organizations across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe.
- Arctic Wolf publishes "Payroll Pirates: Strange New Tides in Business Email Compromise," detailing the Google Meet/Google Ads/Amazon S3 redirect chain, AiTM kit fingerprinting endpoint, Entra sign-in error codes 90014 and 50199, residential-proxy session-refresh cadence, and cross-tenant synchronized MailItemsAccessed collection.
- The Hacker News, TechNadu, Tech Times, and Security Online publish coverage summarizing the Arctic Wolf findings and the Storm-2755 overlap for a broader defender audience.
- GBHackers publishes "Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise," the article that triggered this threat's ingestion into the platform.
- Threadlinqs Intelligence Platform completes deep-dive research on the campaign for detection-engineering and SOC-hunting guidance.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 13 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1608.006, T1583.001, T1583.008, T1566.002, T1557, T1539, T1528, T1078.004, T1556.006, T1087.003