Hackers Poison Office 365 Searches to Siphon Canadian Paychecks
A single mistyped search for Office 365, and your paycheck could land in a hacker's pocket. Microsoft's Storm-2755 crew pulls off payroll heists with chilling precision.
theAIcatchupApr 10, 20263 min read
⚡ Key Takeaways
Storm-2755 poisons Office 365 searches to proxy sessions and steal paychecks via HR emails.𝕏
AiTM bypasses standard MFA; switch to FIDO2 passkeys for real protection.𝕏
Monitor logs for Axios agents and inbox rules hiding financial keywords.𝕏
The 60-Second TL;DR
Storm-2755 poisons Office 365 searches to proxy sessions and steal paychecks via HR emails.
AiTM bypasses standard MFA; switch to FIDO2 passkeys for real protection.
Monitor logs for Axios agents and inbox rules hiding financial keywords.