Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AitM Phishing Targets Microsoft 365 for Payroll Data

AitM Phishing Targets Microsoft 365 for Payroll Data

Posted on August 7, 2026 By CWS

Cybersecurity experts are raising alarms over a significant phishing campaign deploying adversary-in-the-middle (AitM) tactics to breach Microsoft 365 accounts. The primary target is individuals involved in financial operations to access their emails and pertinent data.

Residential Proxies Mask Malicious Activity

According to Arctic Wolf Labs, this campaign leverages residential proxies to mask illegitimate logins as typical consumer activities. This method ensures that compromised sessions are maintained every eight hours, circumventing detection. The campaign is affecting a variety of sectors, including healthcare, education, manufacturing, and government, across the United States, Canada, and Europe.

The tactics bear similarities to those used in Payroll Pirate attacks, which Microsoft tracks under the label Storm-2755. These attacks often reroute salary payments to accounts controlled by the attackers, having been initially documented as early as 2025.

Complex Phishing Techniques Employed

The current wave of attacks involves hundreds of organizations being targeted through email-based phishing. Victims receive voicemail-themed emails leading them to AitM decoy sites, which replicate Microsoft’s authentication flow to capture login credentials and multi-factor authentication codes.

This attack utilizes a six-stage redirection chain that employs credible services such as Google and Amazon S3 to bypass reputation filters. The process begins with a Google Meet redirection link and culminates at Amazon’s S3 infrastructure, which then forwards the user to the phishing site.

Automation Enhances Attack Efficacy

JavaScript on the phishing pages collects detailed information about the visitor’s browser and system, which is then sent to a PHP endpoint. The threat actors use this data to maintain control of the sessions and gather emails from payroll and HR staff involved in financial transactions.

Further scrutiny reveals that these phishing activities originate from residential proxy nodes close to the victim’s location, utilizing geolocation data for optimal proxy selection. This technique helps evade security checks that block unfamiliar IP addresses.

Limited Detection Opportunities

Interestingly, despite gaining access, the attackers have refrained from modifying MFA methods or creating inbox rules, focusing solely on session maintenance and data collection. This restraint minimizes detection risks based on account changes or email anomalies.

In a few cases, attackers manually created inbox rules to move certain emails to the trash and mark them as read, suggesting selective intervention for account manipulation while relying on automation for most tasks.

Arctic Wolf concludes that the use of rotating proxies and centralized automation makes it challenging to trace the campaign back to its phishing origins, thereby complicating detection efforts.

The Hacker News Tags:AiTM phishing, Arctic Wolf, Cybersecurity, email security, finance emails, Microsoft 365, payroll data, phishing campaign, residential proxies, session hijacking, Storm-2755

Post navigation

Previous Post: CHAINDROP Malware Targets Over 400 npm Packages
Next Post: Vishing Group UNC6671 Restructures After Millions in Extortion

Related Posts

Critical Flaw in Google Dialogflow CX Exposed Critical Flaw in Google Dialogflow CX Exposed The Hacker News
Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery The Hacker News
Hotel Wi-Fi Exploited to Distribute Surveillance Trojan Hotel Wi-Fi Exploited to Distribute Surveillance Trojan The Hacker News
Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts The Hacker News
New VVS Stealer Malware Targets Discord Accounts via Obfuscated Python Code New VVS Stealer Malware Targets Discord Accounts via Obfuscated Python Code The Hacker News
Microsoft Warns of ‘Payroll Pirates’ Hijacking HR SaaS Accounts to Steal Employee Salaries Microsoft Warns of ‘Payroll Pirates’ Hijacking HR SaaS Accounts to Steal Employee Salaries The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows Updates Disrupt File History Backups in September 2026
  • Dragos Expands with NetRise and runZero Acquisitions
  • HEIF Image Vulnerability Exploited for Remote Code Execution
  • RatHat Trojan Utilizes AI for Enhanced Android Infiltration
  • New PoC Targets Microsoft Defender with DoS Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows Updates Disrupt File History Backups in September 2026
  • Dragos Expands with NetRise and runZero Acquisitions
  • HEIF Image Vulnerability Exploited for Remote Code Execution
  • RatHat Trojan Utilizes AI for Enhanced Android Infiltration
  • New PoC Targets Microsoft Defender with DoS Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark