Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations in healthcare, education, manufacturing, government, and professional services
Incident: Adversary-in-the-Middle (AitM) phishing campaign targeting Microsoft 365 accounts.
Impact: Unauthorized access to corporate mailboxes and theft of sensitive financial workflow data.
Attacker: Payroll Pirates (Storm-2755/Storm-2657)
Analysis: This campaign leverages a complex redirection chain involving trusted services like Google and Amazon S3 to evade reputation filters. By deploying residential proxies and AitM proxy pages, attackers can bypass multi-factor authentication (MFA) and maintain stealthy, automated sessions. The primary goal is the identification and exploitation of personnel involved in financial and payroll workflows.
Recommendations: Implement FIDO2-compliant phishing-resistant MFA to prevent session hijacking; Deploy strict conditional access policies that require compliant, managed devices; Educate employees to be wary of voicemail-themed lures and unexpected redirection chains
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source