Skip to content

Hackers Use AiTM Session Hijacking to Redirect Employee Salaries in New Storm

Cybersecuritynews •Tushar Subhra Dutta • April 10, 2026

A financially motivated threat group called Storm-2755 has launched a campaign that quietly reroutes employee salary payments to attacker-controlled bank accounts. Targeting Canadian workers, the group uses adversary-in-the-middle (AiTM) techniques to hijack authenticated sessions and bypass multi-factor authentication (MFA), in what researchers have labeled “payroll pirate” attacks.​ The campaign starts with SEO poisoning and malvertising. […]

Extracted Entities

Attack Types (1)

Campaigns (1)