Storm-2755 Payroll Pirates Exploit Employee Trust and MFA Weaknesses
Storm-2755 demonstrates how sophisticated phishing campaigns can bypass traditional security controls through social engineering and technical exploitation. The attackers used SEO poisoning and malvertising to create convincing fake Microsoft 365 login pages, then employed adversary-in-the-middle techniques to intercept and replay authentication tokens even when MFA was enabled. This attack succeeded because employees couldn't distinguish legitimate from fraudulent login pages, and the technical controls failed to detect token replay attacks. The financial impact was direct and immediate, with attackers successfully diverting employee salaries while maintaining persistent access to compromised accounts.
Tactical Insight
Immediate actions
- Deploy phishing-resistant MFA methods like FIDO2 security keys or Windows Hello for Business
- Implement conditional access policies that restrict sign-ins from suspicious locations or devices
- Enable session management controls to detect and block token replay attacks
Long-term improvements
- Establish regular security awareness training focused on identifying sophisticated phishing attempts
- Deploy endpoint detection and response (EDR) solutions to monitor for AiTM proxy activities
- Implement zero trust architecture with continuous session validation
Detection measures
- Monitor for impossible travel scenarios and simultaneous logins from different locations
- Set up alerts for payroll and banking information changes in HR systems
- Deploy web filtering to block known malicious domains and SEO-poisoned results