216.73.216.6

Payroll pirate attacks targeting Canadian employees

· Published 09/04/2026 22:29 · Modified 10/04/2026 10:07

Export JSON

Essential information

Published
09/04/2026 22:29
Modified
10/04/2026 10:07
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
aitm canadian targeting credential phishing cve-2025-27152 malvertising payroll fraud seo poisoning session hijacking token theft
Tags
2026-04-09 CVE-2025-27152 aitm canadian targeting credential phishing malvertising payroll fraud seo poisoning session hijacking token theft
Related entities
1 vulnerabilities (cve), 2 indicators, 2 observables, 1 intrusion sets (apt), 18 techniques (mitre), 1 others

Description

Microsoft Incident Response researchers identified Storm-2755, a financially motivated threat actor conducting payroll pirate attacks against Canadian users. The campaign uses and on generic search terms like "Office 365" to lure victims to a fraudulent sign-in page. Through adversary-in-the-middle techniques, the actor captures authentication tokens and session cookies, bypassing MFA protections. Storm-2755 maintains persistence using Axios HTTP client to replay stolen tokens, then conducts discovery for payroll and HR contacts. The actor impersonates compromised users to socially engineer HR staff or directly manipulates payroll systems like Workday. Malicious inbox rules hide correspondence from victims. Attacks resulted in direct financial losses through redirected salary payments to attacker-controlled bank accounts.

External references