Payroll Pirate Campaign: AiTM Session Hijacking Analysis
Score: 9/10

Payroll Pirate Campaign: AiTM Session Hijacking Analysis

Threat actors Storm-2755 and Storm-2657 utilize AiTM session theft and Microsoft Graph API reconnaissance to execute financial theft by redirecting payroll payments.

Executive Summary

SRA identified an active intrusion campaign dubbed 'Payroll Pirate,' attributed to Storm-2755 and Storm-2657, targeting employees in Canada and US universities. The threat actors employ Adversary-in-the-Middle (AiTM) techniques, likely utilizing the Tycoon 2FA kit, to bypass Multi-Factor Authentication (MFA) and capture Microsoft 365 session tokens.

Technically, the attackers use the stolen tokens to perform automated reconnaissance via the Microsoft Graph API, searching for HR and payroll personnel to facilitate salary redirection. They have been observed using residential proxies to mask their activity while performing bulk directory enumeration. This campaign is highly impactful as it results in direct financial loss through the modification of banking details in platforms like Workday or social engineering of HR staff.

Key Details

Threat Name

Payroll Pirate Campaign

Affects

—

Adversary

Storm-2755 Other Adversaries and Aliases: Storm-2657

Malware/Tools

Tycoon 2FA

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance10
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources