A sophisticated cybercriminal group, known as Payroll Pirates, has been orchestrating phishing campaigns that compromise Microsoft 365 sessions to infiltrate payroll-related email accounts. This operation poses a significant threat to organizations across various sectors, including healthcare, education, manufacturing, government, and professional services in North America and Europe.
Deceptive Voicemail Notifications as Entry Points
The attackers initiate their scheme by dispatching phishing emails that mimic automated voicemail notifications. These messages, adorned with Microsoft logos and fabricated caller details, prompt recipients to access a voicemail portal. Upon clicking the provided link, victims are redirected through multiple services, such as Google Meet and Amazon S3, before landing on a counterfeit Microsoft login page. This intricate redirection chain is designed to evade detection by security filters.
Advanced AiTM Techniques to Bypass MFA
At the heart of this campaign is the use of Adversary-in-the-Middle (AiTM) proxy servers. These proxies intercept the authentication process, relaying genuine Microsoft login pages to the user while capturing their credentials and session tokens in real-time. This method effectively bypasses multi-factor authentication (MFA), allowing attackers to maintain unauthorized access to accounts even after password resets. The AiTM proxies also gather detailed information about the victim’s browser and system settings, enabling the attackers to mimic legitimate user behavior and reduce the likelihood of detection.
Targeted Reconnaissance and Data Exfiltration
Once access is secured, the Payroll Pirates conduct thorough reconnaissance within the compromised Microsoft 365 environment. Utilizing Microsoft Graph API, they identify and access mailboxes belonging to payroll, human resources, finance, and administrative personnel. The attackers specifically search for emails related to invoices, payments, banking details, and internal documents. This targeted approach facilitates the collection of sensitive information that can be exploited for financial fraud, such as redirecting salary payments to accounts under their control.
Notably, the attackers exhibit patience and discretion. They often refrain from immediate malicious actions, opting instead to maintain access and gather intelligence over time. In some instances, they create email rules to move specific messages to the Deleted Items folder and mark them as read, effectively concealing their activities and any responses to fraudulent requests.
The emergence of such sophisticated phishing campaigns underscores the evolving tactics of cybercriminals. Organizations must recognize that traditional security measures, including MFA, may not be sufficient to thwart these advanced threats. It is imperative to implement comprehensive security strategies that encompass user education, robust monitoring of authentication processes, and the deployment of advanced threat detection systems capable of identifying and mitigating AiTM attacks. Vigilance and proactive defense mechanisms are essential to safeguard sensitive payroll and financial information from these increasingly sophisticated cyber threats.