Payroll Pirates Phishing Campaign Hijacks Microsoft 365 Sessions
A new phishing campaign has been identified as 'Payroll Pirates' by cybersecurity firm Arctic Wolf. This attack targets Microsoft 365 sessions and payroll-related mailboxes, even when multi-factor authentication is enabled.
The campaign uses a voicemail alert lure to trick victims into opening a portal, which then redirects them to a fake sign-in page that mimics the real Microsoft login process. This 'AiTM' (adversary-in-the-middle) attack allows attackers to capture authorization codes and session material, making password resets ineffective.
Arctic Wolf analysts found this campaign targeting organizations across various industries in North America and Europe, including healthcare, education, manufacturing, government, and professional services. The attack preserves access for later abuse, often focusing on finance staff and collecting information that enables payroll manipulation.