Executive Summary
SRA identified an active intrusion campaign dubbed 'Payroll Pirate,' attributed to Storm-2755 and Storm-2657, targeting employees in Canada and US universities. The threat actors employ Adversary-in-the-Middle (AiTM) techniques, likely utilizing the Tycoon 2FA kit, to bypass Multi-Factor Authentication (MFA) and capture Microsoft 365 session tokens.
Technically, the attackers use the stolen tokens to perform automated reconnaissance via the Microsoft Graph API, searching for HR and payroll personnel to facilitate salary redirection. They have been observed using residential proxies to mask their activity while performing bulk directory enumeration. This campaign is highly impactful as it results in direct financial loss through the modification of banking details in platforms like Workday or social engineering of HR staff.
