← All briefs
high August 13, 2026

Payroll Pirates: Microsoft 365 Adversary-in-the-Middle Campaign Hijacking Finance and Payroll Mailboxes

Source report →

An adversary-in-the-middle phishing operation is compromising Microsoft 365 accounts across organizations in the United States, Canada, and Europe. The activity overlaps with the payroll-focused cluster Microsoft tracks as Storm-2755 and is centered on financial fraud: identifying employees responsible for payroll and direct-deposit processes, accessing their correspondence, and using that information to redirect salary payments through platforms such as Workday and ADP.

Delivery begins with voicemail-themed phishing emails containing fabricated caller, duration, and reference details and directing recipients to an organization-branded voicemail portal. Rather than linking directly to attacker infrastructure, the embedded URL passes through a chain of legitimate services, including Google Meet redirection, Google Ads, Campaign Manager tracking, and Amazon S3, before reaching adversary-controlled infrastructure. The redirector and proxy domains use Microsoft-themed subdomains and are typically newly registered. Before presenting the sign-in page, the proxy fingerprints the victim’s browser and geolocates the connection, using the result to select a geographically consistent proxy exit node.

The adversary uses an AiTM proxy to relay the genuine Microsoft authentication flow, rewriting Microsoft authentication endpoints beneath an attacker-controlled domain. At the callback stage, the proxy captures the authorization code and identity token after the victim completes authentication and any required MFA. Initial post-compromise sign-ins appear within minutes from residential proxy infrastructure and carry anomalous user agents, including browser and operating-system combinations inconsistent with the reported Microsoft client, alongside an uncommon authentication error involving a first-party application. The stolen sessions are then reused on an approximately eight-hour cadence under the Microsoft Outlook client identity, while source IP, ASN, and geography rotate but the session identifier remains constant. Firefox and Python Requests user agents further distinguish the automated activity from expected Outlook behavior.

Post-compromise activity is primarily automated. Microsoft Graph is used to identify users in payroll, human resources, finance, and administrative roles, followed by broader directory enumeration through a scripting-library user agent. The same tooling then accesses mailbox content related to payroll, invoices, payments, banking, benefits, and internal documents. Mailbox reads exhibit an unusual application/API identifier pairing and confirm retrieval of message content rather than simple enumeration. Access occurring within seconds across unrelated tenants points to centralized tooling operating multiple compromised accounts in parallel. In a smaller number of cases, a human operator connects from hosting-provider infrastructure and creates inbox rules that move messages to Deleted Items and mark them as read.

DOMAIN 38
idp.keyreniao.com
idp.korminel.com
idp.kualabemo.com
int.camberwolis.com
mslogin.milocaroline.com
msauth.monlinelogicaline.com
msonline.logicalineonline.com
office.ofreace.com
office.ofercarc.com
office.ofrecie.com
office.ofreice.com
office.ofrecre.com
office.ocrifere.com
office.ocifire.com
login.oficarine.com
login-microsoftonline.offirmtm.com
wisemediapa-ttern.digital
sky2025forge.digital
skyprimeworks.digital
1systemsevolve.digital
xsyst-emsquantum.digital
tec-hnoplatform2025.digital
evolveelevateunion.digital
offirmtm.com
keyreniao.com
korminel.com
kualabemo.com
milocaroline.com
monlinelogicaline.com
logicalineonline.com
ofrecie.com
ofreace.com
ofreice.com
ofrecre.com
ofercarc.com
ocrifere.com
ocifire.com
oficarine.com
IP ADDRESS 7
153.92.1.166
72.62.0.181
31.97.76.103
177.7.56.248
187.124.129.44
194.5.157.204
145.223.100.123
URL 4
https://msonline.logicalineonline.com/https://login.microsoftonline.com/common/GetCredentialType
https://msonline.logicalineonline.com/https://login.microsoftonline.com/common/login
https://msonline.logicalineonline.com/https://login.microsoftonline.com/common/SAS/BeginAuth
https://msonline.logicalineonline.com/https://login.microsoftonline.com/common/SAS/EndAuth

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Microsoft Outlook Application Sign In With Non Edge User Agent
  • MailItemsAccessed With Anomalous Outlook API Pairing
  • Microsoft Graph Directory Search Across Multiple Attributes for Finance Personnel
  • Repeated Microsoft Graph Directory Searches for Finance Personnel
  • First Party Microsoft Application Sign In With Missing Nonce Error
  • Email Link Click Chaining a Google Redirector to Cloud Object Storage
  • Email Subject Combining Urgency Keyword and Reference Identifier
  • Outbound Web Request to a Microsoft 365 Lookalike Registrable Domain
  • Sign In Reporting a Mobile Browser on a Desktop Operating System