Payroll Pirates Hijack M365 Sessions with Voicemail-Themed Phishing Emails
A new phishing campaign, linked to the Payroll Pirates activity cluster known as Storm-2755, has been identified by Arctic Wolf. This campaign targets organizations in various sectors, including healthcare, education, manufacturing, government, and professional services.
The attackers use adversary-in-the-middle (AiTM) phishing pages to steal authenticated Microsoft 365 sessions. They are primarily interested in employees who handle payroll, HR, finance, invoices, payments, and banking information.
The campaign begins with voicemail-themed phishing emails impersonating an automated call-notification service. These emails include fabricated caller IDs, dates, durations, and reference numbers to create urgency.