# The Payroll Heist Running at Eight-Hour Intervals Inside Your Microsoft 365 Tenant
When attackers want your salary payments rerouted to their accounts, they don't need to break your MFA. They just need to sit quietly between you and Microsoft's login page long enough to capture everything.
That's the mechanic behind a phishing campaign Arctic Wolf Labs documented this week — one that has touched hundreds of organizations across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe. The attackers behind it aren't smashing and grabbing. They're patient, automated, and methodical. They find the payroll people, read their email, and wait.
## The Redirect Maze That Kills Your Reputation Filter
The delivery mechanism is worth examining in detail, because it represents the current state of the art in phishing infrastructure.
Victims receive voicemail-themed phishing emails — a reliably effective pretext because people feel urgency about missed calls. Clicking the link doesn't send them straight to a fake login page. Instead, they travel through a six-stage redirect chain that runs entirely through services your security stack is configured to trust:
1. A Google Meet link-redirect URL
2. Through Google's outbound-link infrastructure
3. Into a Google Campaign Manager /ddm/clk click tracker
4. To an HTML object hosted on Amazon S3
5. The S3 page redirects to the actual AitM phishing infrastructure
6. Which proxies the real Microsoft OAuth flow while silently capturing credentials and MFA codes
This is an anti-reputation-filter construction. By the time any URL in that chain reaches a security gateway, it carries the brand trust of Google or Amazon. Each hop is technically legitimate. The malicious destination is buried at the end. Signature-based and reputation-based filters, without behavioral analysis of the full chain, see nothing to block.
The AitM page itself fingerprints every visitor — browser type, OS, screen dimensions, WebGL vendor, WebDriver status, time zone, cookie support — before routing them anywhere. That fingerprinting data gets exfiltrated to a PHP endpoint. The geolocation API check (api.country.is) is particularly telling: the campaign stores the victim's country in a cookie with a seven-day expiration, then uses that data to select a residential proxy exit node in the victim's own country for all subsequent malicious logins.
That proxy selection is why the initial sign-in events look local. Anomaly detection systems that flag logins from foreign IPs or unusual locations see nothing suspicious — the attacker is appearing to sign in from the same country as the victim, via residential IP addresses that belong to ordinary consumers.
## Automated Persistence, Timed Like Clockwork
Account takeover is stage one. The campaign's real goal is more patient.
After gaining access, the threat actors don't immediately redirect payroll. They read email. Specifically, they collect messages from HR and payroll personnel who handle financial workflows — building a map of who approves what, who gets paid what, and how change requests get processed. The session isn't abandoned after the initial compromise. Automated activity maintains the hijacked session at eight-hour intervals, rotating through residential proxy addresses each time. The login events report implausible browser and OS combinations — Safari mobile on Windows 10, for instance — which should trigger investigation but apparently does not do so at scale.
This campaign has clear ties to what Microsoft tracks as Storm-2755, part of the broader Payroll Pirates cluster. Microsoft separately tracks a related threat as Storm-2657. Payroll Pirates has been active since at least early 2025, and the goal is consistent: hijack employee accounts, collect enough context to make fraudulent payroll change requests credible, reroute salary payments to attacker-controlled accounts. The payout isn't immediate — it requires reconnaissance. The eight-hour persistence loop is that reconnaissance running on autopilot.
## Who's Actually at Risk Right Now
Healthcare, education, and government are in the explicit victim list — sectors that tend to have complex HR workflows, distributed payroll systems, and in some cases less mature phishing simulation programs. Manufacturing and professional services round out the exposure. These aren't niche targets; this is essentially every medium-to-large organization in North America and Europe that runs Microsoft 365.
The specific personnel at risk are payroll administrators, HR staff with system access, finance team members who handle wire transfers or direct deposit changes, and their managers who appear in approval chains. Attackers aren't after the CISO's account — they're after the accounts that can make a payroll change request look legitimate.
---
## HackWire Analysis
The disturbing thing about this campaign isn't the AitM technique itself — that's been documented for years, and products like Microsoft's Entra ID now offer some phishing-resistant MFA options. What should concern security teams is the defense evasion stack layered around the basic credential theft.
We're watching a systematic dismantling of "trust by reputation" as a security control. Blocking Google Meet URLs, Google Ads tracking links, or Amazon S3 objects isn't operationally realistic for most organizations. These are core business infrastructure services. Attackers know this and have built their delivery chain specifically to hide inside the trust that enterprises have granted Google and Amazon.
The geolocation-matched proxy selection is the second layer that matters. Conditional access policies built around geographic anomalies — "flag logins from foreign countries" — are being defeated not by technical bypass but by logistics. The attackers are simply showing up from the right country. This arms race between behavioral detection and geographically aware proxy networks is going to continue, and defenders relying on location-based anomaly detection alone are going to keep losing.
The eight-hour session renewal cadence is also worth flagging to SOC teams specifically. This looks like legitimate refresh behavior on surface-level authentication logs. You're looking for session tokens being renewed at suspiciously regular intervals from rotating residential IPs — that's not a signature, that's a behavioral pattern that requires correlation across multiple log sources.
Short-term recommendations for defenders: enforce phishing-resistant MFA (FIDO2 hardware keys or passkeys) for all payroll and HR personnel, configure Conditional Access to require managed compliant devices for any session that accesses HR or payroll systems, and build detection rules for session token reuse from rotating residential IP blocks at clock-regular intervals. The implausible browser/OS combinations — Safari on Windows — should be easy wins in your SIEM if you're not already alerting on them.
Longer term, the industry needs to reckon with the fact that AitM-resistant MFA adoption is still crawling while these campaigns scale up. The attackers are already past the "does the target have MFA?" question. The question now is whether the MFA is actually phishing-resistant — and for most organizations, it still isn't.
— HackWire Editorial
---
## Related Coverage