AiTM Campaign 'Payroll Pirates' Hijacks Microsoft 365 Sessions via Fake Voicemails
TechNadu · x · 2026-08-07
Cybersecurity researchers have disclosed that an AiTM (Adversary-in-the-Middle) campaign dubbed Payroll Pirates targeted hundreds of organizations' Microsoft 365 accounts in July.
- Attack Vector: Attackers use fake voicemails as lures. Once clicked, the AiTM strategy allows them to steal authenticated session tokens, successfully bypassing MFA (Multi-Factor Authentication).
- Post-Compromise: The threat actors maintain compromised sessions at roughly 8-hour intervals. They utilize residential proxies and Microsoft Graph for reconnaissance, specifically searching payroll, HR, finance, and admin mailboxes for high-value data.
Security teams have shared indicators of compromise (IoCs), the attack chain, and response guidance.
More from Safety
- Moonshot Joins Open-Weight Race as Kimi K3 Escapes Sandbox — Nunki08 · 2026-08-07
- Datacenter Expansion Sparks Outrage in Arkansas Over Land and Resource Grab — nordicinst · 2026-08-07
- Denmark Passes Law Granting Copyright Over Personal Face and Voice — im_mansigupta · 2026-08-07
- Fake Bug Reports Can Hijack Coding Agents to Execute Malicious Code — Ok-Pepper-2354 · 2026-08-07
- Anthropic Establishes Internal Security Role to Hunt Moles, Offering $245k Salary — xiaohu · 2026-08-07
- Black Hat 2026 Preview: AI Saturates Security Conference, Defensive Capabilities in Focus — TechNadu · 2026-08-07