Gbhackers
Payroll Pirate Campaign Targets Payroll Systems Using AiTM Session Hijacking
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The 'Payroll Pirate' campaign has emerged, utilizing advanced phishing and AiTM session hijacking to bypass MFA and reroute payroll disbursements. Targeting mid-market and enterprise organizations, attackers exploit payroll and HR portals, chaining credential theft and real-time session interception. The attack begins with phishing payroll administrators, capturing MFA tokens through an AiTM proxy to hijack sessions. Once inside, attackers modify payment instructions and create fraudulent vendor accounts while evading detection. The campaign employs sophisticated social engineering techniques, including deepfake-style communications. Funds are laundered through mule accounts and cryptocurrency exchanges, complicating recovery efforts. Recent observations indicate that this method can bypass many MFA implementations, necessitating enhanced security measures. Organizations are advised to implement step-up authentication for high-risk actions and monitor for behavioral anomalies.
Key Points: • The Payroll Pirate campaign uses AiTM session hijacking to bypass MFA and reroute payroll. • Attackers target payroll and HR portals at mid-market and enterprise organizations. • Real-time session hijacking allows attackers to modify payment details without detection.