AitM Phishing Campaign Targets Microsoft 365 Payroll and Finance Roles
Attackers use residential proxies and trusted cloud services to hijack accounts and evade security alerts.
A sophisticated phishing campaign is utilizing adversary-in-the-middle (AitM) techniques to hijack Microsoft 365 accounts, specifically targeting personnel in payroll, HR, and finance. The operation leverages a complex redirection chain and residential proxies to bypass traditional security filters and maintain long-term access to sensitive corporate data.
According to analysis by Arctic Wolf Labs, the attack begins with voicemail-themed emails that use Microsoft branding to create a sense of urgency. To evade reputation filters, the campaign employs a multi-stage redirection chain that abuses trusted infrastructure, including Google Meet, Google Ads, and Amazon S3 buckets. Once a victim is lured into providing credentials, the attackers use residential proxies—specifically anyIP—to match the victim's country, which Arctic Wolf Labs notes is designed to "disguise malicious sign-ins as ordinary consumer traffic."
The Payroll Pirate Connection
This activity is part of a broader trend involving financially motivated threat clusters known as "Payroll Pirates," including groups tracked by Microsoft as Storm-2755. These clusters typically focus on hijacking employee accounts to reroute salary payments to attacker-controlled accounts. The current campaign shares significant tactical and behavioral overlaps with Storm-2755, signaling a coordinated effort to penetrate high-value administrative roles.
Why Stealth is the Priority
What makes this campaign particularly dangerous is its avoidance of typical Business Email Compromise (BEC) behaviors. Unlike many attackers, these actors do not immediately change multi-factor authentication (MFA) methods or create widespread inbox rules, both of which usually trigger security alerts. Instead, they maintain compromised sessions through automated activity occurring at approximately eight-hour intervals. Arctic Wolf Labs stated that by avoiding these common behaviors, the threat actors "limited opportunities for early detection based on account modification or outbound email abuse."
Industry Impact and Next Steps
The campaign has targeted organizations across the U.S., Canada, and Europe, with a heavy focus on the healthcare, education, manufacturing, government, and professional services sectors. Once inside a network, the attackers utilize the Microsoft Graph API to enumerate and collect emails from users in administrative, finance, and payroll functions.
Security teams are advised to monitor for unusual sign-in patterns that match consumer residential IP ranges and to audit Graph API usage for unauthorized enumeration of employee roles. While the primary goal appears to be financial theft via payroll manipulation, the ability of these actors to maintain stealthy, long-term access suggests a high level of operational discipline that could be used for broader data exfiltration.