Affected Systems
Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe. Hundreds of organizations targeted in July 2026, with focus on payroll, HR, and finance personnel.
Exploitation Status
Active exploitation confirmed. Hundreds of organizations targeted in July 2026 with successful intrusions observed. Campaign uses adversary-in-the-middle (AitM) phishing infrastructure with automated session maintenance at 8-hour intervals. Tactically overlaps with Storm-2755 (Payroll Pirate) attacks tracked by Microsoft since early 2025.
Business Impact
Attackers compromise Microsoft 365 accounts via AitM phishing that bypasses MFA, then maintain persistent access using residential proxies matched to victim geography. Post-compromise activity focuses on identifying and harvesting emails from payroll, HR, and finance staff. Campaign uses legitimate services (Google Meet, Google Ads, Amazon S3) in six-stage redirection chain to evade email filters. Automated session refresh every 8 hours with rotating residential IPs makes detection difficult. Limited post-compromise actions (no MFA changes, device registration, or lateral phishing) reduce detection opportunities. Primary risk is financial fraud through payroll diversion and exposure of sensitive financial communications.
Urgency
🔴 Immediate
Recommended Actions
- Enable conditional access policies in Microsoft 365 that block sign-ins from residential proxy IP ranges and flag impossible travel or implausible browser/OS combinations
- Monitor Microsoft 365 sign-in logs for recurring authentication events at regular intervals (especially 8-hour patterns) with changing source IPs but identical SessionIDs
- Block or scrutinize emails containing Google Meet redirect URLs, Google Ads click trackers (/ddm/clk), and Amazon S3-hosted HTML redirects in email gateway rules
- Hunt for Microsoft Graph API enumeration activity targeting user accounts with payroll, HR, finance, or admin keywords in mailboxes
- Review inbox rules across finance and payroll user accounts for automated moves to Deleted Items or mark-as-read actions created within past 90 days
