A phishing wave that masquerades as voicemail notifications is quietly taking over Microsoft 365 mailboxes to mine payroll and finance conversations. Arctic Wolf Labs says the campaign, which abuses adversary-in-the-middle (AitM) techniques, targeted hundreds of organizations last month and scored intrusions across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe.
The attack chain routes victims through a six-stage redirection path built on reputable infrastructure, including Google, Google Meet, Google Ads, and Amazon S3, to slip past reputation-based filters. The final stop is a decoy page that proxies the real Microsoft sign-in flow, harvesting credentials and multi-factor authentication codes along the way.
The phishing pages fingerprint the visitor’s browser and pull a country code from a geolocation API. Arctic Wolf’s controlled testing found malicious sign-ins originating within minutes from residential proxy exit nodes in the victim’s own country, a sign the operators pick geographically matched proxies to dodge location-based defenses.
Once inside, the attackers lean on the Microsoft Graph API to locate users tied to payroll, HR, finance, and administrative roles, then pull emails touching salaries, invoices, payments, banking, benefits, and internal documents. Automation keeps sessions alive at roughly eight-hour intervals from rotating residential proxy addresses; the session ID stays constant while the source IP, ASN, and geography change.
Arctic Wolf ties the activity to the Payroll Pirate cluster Microsoft tracks as Storm-2755. In most intrusions the operators stuck to session upkeep, reconnaissance, and mailbox collection, with no MFA-method changes, device registration, or inbox rule creation observed.
