The emails that successfully move company money are almost always the quietest in the inbox. When adversaries weaponize trusted enterprise infrastructure, standard authentication checks confirm that the infrastructure itself is real, but they fail to ask what the message actually wants to achieve.
The "Payroll Pirates" campaign (Storm-2755) is an active, financially motivated phishing operation that hijacks Microsoft 365 accounts to quietly search finance and payroll mailboxes. Earlier waves of Storm-2755 relied on SEO poisoning and malvertising—pushing fraudulent domains like bluegraintours[.]com to the top of search results for queries like "Office 365". However, the July 2026 wave observed by Arctic Wolf Labs shifted heavily to email delivery. The operators utilize sophisticated adversary-in-the-middle (AiTM) techniques to steal active session cookies and OAuth access tokens at the exact moment they are issued. This allows attackers to take over accounts and blend into legitimate user activity without ever needing a password or defeating MFA directly.
The Payroll Pirates string together legitimate services so that no single hop triggers a block from legacy secure email gateways (SEGs).
The 6-Stage Evasion Chain:[ Fake Voicemail Lure ] ➔ [ Google Meet Redirect ] ➔ [ Campaign Manager Tracker ] ➔ [ AWS S3 HTML Object ] ➔ [ Fingerprint Cloaking Gate ] ➔ [ AiTM Proxy ]
Once the session is hijacked, the attackers operate quietly to avoid triggering standard identity alerts, creating a highly specific forensic footprint for SOC teams to hunt.
ResultType 90014 (a required credential field was missing) originating from US mobile carrier IP space. To maintain the sessions, the attackers utilize rotating residential ISP addresses, frequently displaying an anomalous Axios 1.7.9 user-agent string instead of a standard browser.[graph.microsoft.com/v1.0/users](https://graph.microsoft.com/v1.0/users). They use filters for attributes to build a target list directly from the tenant's directory, hunting for staff in payroll, HR, and finance.The only way to catch an AiTM campaign built entirely from legitimate components is to analyze its underlying intent. StrongestLayer’s TRACE engine achieves a confident pre-delivery block against the Payroll Pirates by breaking down the attack structurally at the email layer:
The weaponization of legitimate SaaS platforms and authorization flows is accelerating. Our threat intelligence team is actively tracking secondary campaigns that utilize similar evasion techniques:
Stop AiTM Attacks Before the Click
Advanced campaigns use fingerprint and geo-cloaking to serve benign content to security scanners, causing traditional URL detonation to achieve only a "PARTIAL" verdict against this threat. StrongestLayer’s TRACE engine eliminates this blind spot by fusing intent reasoning with the URL chain to reach a confident "DETECT" verdict before the email is ever delivered.
The "Payroll Pirates" (Storm-2755) campaign represents a defining shift in the threat landscape. Attackers no longer need to write custom malware or exploit complex zero-day vulnerabilities when they can simply abuse the inherent trust of cloud infrastructure (Google Meet, Google Ads, AWS S3) and the inherent flaws of password-based MFA.
As legacy SEGs struggle with reputation laundering and fingerprint cloaking, security teams must recognize that infrastructure reputation is no longer a proxy for safety. Defending against modern AiTM campaigns requires moving beyond static domain checks and signature matching toward real-time intent reasoning—analyzing what a message is trying to achieve before it ever reaches the user's inbox.
The primary objective is financial fraud through payroll diversion. Once attackers hijack an employee's Microsoft 365 account, they conduct internal reconnaissance using the Microsoft Graph API to target HR and finance personnel. They then alter direct-deposit banking details—either by submitting fraudulent requests to HR or by logging directly into HR platforms like Workday—to redirect upcoming salary payments to attacker-controlled accounts.
The campaign uses an Adversary-in-the-Middle (AiTM) proxy architecture. When a victim clicks the phishing link and enters their credentials on the lookalike site, the proxy relays those inputs to the legitimate Microsoft login endpoint in real time. The user completes the MFA prompt on their authentic authenticator app or device, but the proxy intercepts the resulting post-authentication session cookie/token. The attackers then import this token into their own session, giving them full account access without needing to defeat the MFA mechanism itself.
Traditional SEGs fail primarily due to reputation laundering and fingerprint cloaking:
SOC analysts and threat hunters should look for the following indicators in Microsoft Entra ID / Exchange logs:
[graph.microsoft.com/v1.0/users](https://graph.microsoft.com/v1.0/users) filtering for terms like payroll, hr, or finance.Axios 1.7.9 or non-standard browser signatures coming from residential proxy IP ranges.ResultType 90014 (missing credential fields) originating from US mobile carrier networks.While traditional URL sandboxes get trapped by fingerprint cloaking gates (resulting in a "PARTIAL" verdict), StrongestLayer’s TRACE engine analyzes the intent genome of the message. TRACE identifies the high-risk combination of a voicemail portal pretext attempting to funnel an enterprise user into a Microsoft authentication workflow directly within the email body. By fusing this intent reasoning with sender signals and live redirect chain telemetry, TRACE reaches a confident DETECT verdict before the email reaches the user's inbox.
Be the first to get exclusive offers and the latest news
Deploy in minutes, not months. Zero tuning. See what your current tools are missing.