Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Payroll Pirates: Strange New Tides in Business Email Compromise

msauth.monlinelogicaline.com

TLP:CLEAR
Active

Domain

Description

Arctic Wolf is tracking an active, widespread phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle (AiTM) techniques. The operation employs voicemail-themed phishing emails that redirect victims through multiple legitimate services to AiTM proxy infrastructure, which intercepts authentication sessions even when multi-factor authentication is enabled. Once compromised, threat actors use residential proxies to maintain access, conducting automated sign-ins at eight-hour intervals while collecting email from personnel involved in financial workflows. The campaign uses Microsoft Graph for reconnaissance targeting payroll, HR, and finance users, followed by coordinated mailbox collection. Activity affects organizations across healthcare, education, manufacturing, government, and professional services sectors in the United States, Canada, and Europe. The campaign shares characteristics with Microsoft-tracked Storm-2755 activity cluster.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Payroll Pirates: Strange New Tides in Business Email Compromise
Pattern Type
STIX
Confidence
75%
Valid From
Aug 7, 2026 10:00
Total Sightings
0
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of msauth.monlinelogicaline.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.