Session Replay Enables Silent Payroll Theft in Microsoft 365 Phishing
Storm-2755 is not just stealing Microsoft 365 passwords; it is capturing and replaying live session tokens to bypass legacy MFA protections. This allows attackers to maintain active sessions without re-authenticating, turning a phishing campaign into a stealthy business-process abuse operation. The attackers can silently redirect employee paychecks by exploiting valid sessions rather than relying solely on stolen credentials.
Microsoft researchers confirm that Storm-2755 uses SEO poisoning and malvertising to lure victims to fake Microsoft 365 login pages. These pages proxy the entire authentication flow, capturing session tokens that bypass non-phishing-resistant MFA. The attackers then use these tokens to access email accounts, search for payroll-related information, and send fraudulent direct deposit change requests to HR staff. In some cases, they directly manipulate HR software to divert salaries.
This campaign highlights that standard incident response focused on password resets and MFA enforcement may miss ongoing session hijacking risks. Attackers holding valid session tokens can continue operating as legitimate users until tokens are revoked. The threat is especially urgent for Canadian organizations with employee self-service payroll workflows, as the financial impact extends beyond email compromise to payroll fraud.