Microsoft DART researchers identified a new campaign by the financially motivated threat actor Storm-2755, which targets Canadian users with payroll pirate attacks. These attacks involve compromising user accounts through malvertising and SEO poisoning to redirect salary payments to attacker-controlled bank accounts, bypassing MFA using AiTM techniques.
This development is critical for developers and tech professionals as it highlights the evolving sophistication of credential theft methods and emphasizes the need for robust phishing-resistant MFA implementations and continuous access evaluation policies.
Read the full article at Malware Analysis, News and Indicators - Latest topics
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



