Payroll Pirates Phishing Campaign Hijacks Microsoft 365 Sessions
Cyber attackers are targeting Microsoft 365 sessions and payroll-related mailboxes in a phishing campaign dubbed 'Payroll Pirates.' The campaign uses automated call notifications as a lure to trick victims into opening a voicemail portal, which then directs them to a fake sign-in page that relays the real Microsoft login process. This is an example of an AiTM (adversary-in-the-middle) attack, where the attacker places itself between the victim and Microsoft, capturing the authorization code and session material after the victim completes sign-in and multi-factor authentication.
The attackers use a multi-stage redirect chain that abuses Google Meet, Google advertising links, and Amazon S3 hosting to make the malicious destination harder for reputation filters to spot. They also check browser details, screen settings, language, location, and automation clues before forwarding visitors to the fake sign-in page. This makes it difficult to stop with conventional MFA (multi-factor authentication) alone.
Once inside the system, the attackers preserve access, identify finance staff, and collect information that could enable later payroll abuse. In some cases, they create rules that move messages to Deleted Items and mark them read, potentially hiding responses while a financial request is pursued.