Payroll pirate attacks targeting Canadian employees
Essential information
- Published
- 09/04/2026 22:29
- Modified
- 10/04/2026 10:07
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- aitm canadian targeting credential phishing cve-2025-27152 malvertising payroll fraud seo poisoning session hijacking token theft
- Tags
- 2026-04-09 CVE-2025-27152 aitm canadian targeting credential phishing malvertising payroll fraud seo poisoning session hijacking token theft
- Related entities
- 1 vulnerabilities (cve), 2 indicators, 2 observables, 1 intrusion sets (apt), 18 techniques (mitre), 1 others
Description
Microsoft Incident Response researchers identified Storm-2755, a financially motivated threat actor conducting payroll pirate attacks against Canadian users. The campaign uses malvertising and SEO poisoning on generic search terms like "Office 365" to lure victims to a fraudulent sign-in page. Through adversary-in-the-middle techniques, the actor captures authentication tokens and session cookies, bypassing MFA protections. Storm-2755 maintains persistence using Axios HTTP client to replay stolen tokens, then conducts discovery for payroll and HR contacts. The actor impersonates compromised users to socially engineer HR staff or directly manipulates payroll systems like Workday. Malicious inbox rules hide correspondence from victims. Attacks resulted in direct financial losses through redirected salary payments to attacker-controlled bank accounts.