A widespread phishing campaign is compromising Microsoft 365 accounts with adversary-in-the-middle login pages that capture session material even when MFA is enabled, then using those identities to target payroll, HR, finance, and administrative staff across healthcare, education, manufacturing, government, and professional services in the United States, Canada, and Europe. Arctic Wolf said the activity aligns technically and behaviorally with Microsoft-tracked Storm-2755 (also known as Payroll Pirates), with attackers maintaining access through rotating residential proxies and automated session activity roughly every eight hours while quietly collecting mailbox data tied to financial workflows.
Reporting also shows the intrusions can progress without additional device compromise, shifting instead into identity-plane lateral movement inside Entra ID and Microsoft 365. After an initial phish, attackers can use stolen session tokens to enumerate the tenant through Microsoft Graph, register a malicious Entra ID application, create a service principal, grant permissions such as Mail.Read and Mail.Send, and access other users’ mailboxes, including executives, before sending fraudulent messages through Graph API that pass SPF and DKIM checks. Defenders were urged to correlate cloud identity, Graph, sign-in, and email telemetry for signals including OfficeHome error 90014, anomalous Outlook sign-ins with Firefox user agents, repeated SessionID reuse across changing IPs and geographies, suspicious app registrations, credential additions to service principals, and unusual application access to user mailboxes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Arctic Wolf observed hundreds of organizations across the United States, Canada, and Europe targeted by a widespread email campaign in July 2026. The operation used voicemail-themed lures and adversary-in-the-middle phishing pages to compromise Microsoft 365 accounts, including victims in healthcare, education, manufacturing, government, and professional services.
Detect described an attack path in Microsoft 365 and Entra ID where a phished user's session token is used to enumerate the tenant, register a malicious Entra application, create a service principal, and grant it permissions such as Mail.Read and Mail.Send. The article's example culminates in the service principal accessing the CFO's mailbox and sending a fraudulent wire-transfer reply through Microsoft Graph API.
Arctic Wolf reported that the campaign's technical and behavioral characteristics overlap with the Payroll Pirates cluster tracked by Microsoft as Storm-2755. The report highlighted durable detection signals including OfficeHome error 90014, anomalous Outlook sign-ins with Firefox user agents, SessionID reuse across changing IPs, and a distinctive MailItemsAccessed telemetry pattern.
Following account compromise, the actor used Microsoft Graph to identify payroll, HR, finance, and administrative users and then accessed messages related to payroll, invoices, payments, banking, benefits, and internal documents. In Defender XDR, this reconnaissance generated Suspicious Exchange Online Graph Reconnaissance Activity alerts, and successful Bind events confirmed message retrieval.
After successful authentication through the AiTM infrastructure, malicious OfficeHome sign-ins typically began within minutes and often recurred 11 to 24 hours later at roughly eight-hour intervals. Arctic Wolf said the actor reused the same SessionID across changing IPs, ASNs, and geographies, indicating centralized automation maintaining compromised sessions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcemalware.news
Open sourcearcticwolf.com
Open sourcedetect.fyi
Open sourcesra.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.