Payroll Pirates: Microsoft 365 Adversary-in-the-Middle Campaign Hijacking Finance and Payroll Mailboxes
Source report →An adversary-in-the-middle phishing operation is compromising Microsoft 365 accounts across organizations in the United States, Canada, and Europe. The activity overlaps with the payroll-focused cluster Microsoft tracks as Storm-2755 and is centered on financial fraud: identifying employees responsible for payroll and direct-deposit processes, accessing their correspondence, and using that information to redirect salary payments through platforms such as Workday and ADP.
Delivery begins with voicemail-themed phishing emails containing fabricated caller, duration, and reference details and directing recipients to an organization-branded voicemail portal. Rather than linking directly to attacker infrastructure, the embedded URL passes through a chain of legitimate services, including Google Meet redirection, Google Ads, Campaign Manager tracking, and Amazon S3, before reaching adversary-controlled infrastructure. The redirector and proxy domains use Microsoft-themed subdomains and are typically newly registered. Before presenting the sign-in page, the proxy fingerprints the victim’s browser and geolocates the connection, using the result to select a geographically consistent proxy exit node.
The adversary uses an AiTM proxy to relay the genuine Microsoft authentication flow, rewriting Microsoft authentication endpoints beneath an attacker-controlled domain. At the callback stage, the proxy captures the authorization code and identity token after the victim completes authentication and any required MFA. Initial post-compromise sign-ins appear within minutes from residential proxy infrastructure and carry anomalous user agents, including browser and operating-system combinations inconsistent with the reported Microsoft client, alongside an uncommon authentication error involving a first-party application. The stolen sessions are then reused on an approximately eight-hour cadence under the Microsoft Outlook client identity, while source IP, ASN, and geography rotate but the session identifier remains constant. Firefox and Python Requests user agents further distinguish the automated activity from expected Outlook behavior.
Post-compromise activity is primarily automated. Microsoft Graph is used to identify users in payroll, human resources, finance, and administrative roles, followed by broader directory enumeration through a scripting-library user agent. The same tooling then accesses mailbox content related to payroll, invoices, payments, banking, benefits, and internal documents. Mailbox reads exhibit an unusual application/API identifier pairing and confirm retrieval of message content rather than simple enumeration. Access occurring within seconds across unrelated tenants points to centralized tooling operating multiple compromised accounts in parallel. In a smaller number of cases, a human operator connects from hosting-provider infrastructure and creates inbox rules that move messages to Deleted Items and mark them as read.
IOCs (49)
Scan your environment for IOCs →DOMAIN 38
idp.keyreniao.comidp.korminel.comidp.kualabemo.comint.camberwolis.commslogin.milocaroline.commsauth.monlinelogicaline.commsonline.logicalineonline.comoffice.ofreace.comoffice.ofercarc.comoffice.ofrecie.comoffice.ofreice.comoffice.ofrecre.comoffice.ocrifere.comoffice.ocifire.comlogin.oficarine.comlogin-microsoftonline.offirmtm.comwisemediapa-ttern.digitalsky2025forge.digitalskyprimeworks.digital1systemsevolve.digitalxsyst-emsquantum.digitaltec-hnoplatform2025.digitalevolveelevateunion.digitaloffirmtm.comkeyreniao.comkorminel.comkualabemo.commilocaroline.commonlinelogicaline.comlogicalineonline.comofrecie.comofreace.comofreice.comofrecre.comofercarc.comocrifere.comocifire.comoficarine.comIP ADDRESS 7
153.92.1.16672.62.0.18131.97.76.103177.7.56.248187.124.129.44194.5.157.204145.223.100.123URL 4
https://msonline.logicalineonline.com/https://login.microsoftonline.com/common/GetCredentialTypehttps://msonline.logicalineonline.com/https://login.microsoftonline.com/common/loginhttps://msonline.logicalineonline.com/https://login.microsoftonline.com/common/SAS/BeginAuthhttps://msonline.logicalineonline.com/https://login.microsoftonline.com/common/SAS/EndAuthDetections (10)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- Microsoft Outlook Application Sign In With Non Edge User Agent
- MailItemsAccessed With Anomalous Outlook API Pairing
- Microsoft Graph Directory Search Across Multiple Attributes for Finance Personnel
- Repeated Microsoft Graph Directory Searches for Finance Personnel
- First Party Microsoft Application Sign In With Missing Nonce Error
- Email Link Click Chaining a Google Redirector to Cloud Object Storage
- Email Subject Combining Urgency Keyword and Reference Identifier
- Outbound Web Request to a Microsoft 365 Lookalike Registrable Domain
- Sign In Reporting a Mobile Browser on a Desktop Operating System