Last seven days
- First activity
- Sep 4, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 15 hostnames
C2 tracking
Derp observations, rolling seven-day window
Samples
3c6ebed12f5698f11b85b291f7bda251e3f8a0aa53bfc0e56d70f6468f4e0cc1 225b3b2b3185447d8b436e5505419a37361a17168293e310c619161b94edb8c9 bfbf312d74d68948700eb5f33c50de5d641ab3327f3077641de7ea41c2347122 497eec4aac283db02a8a1653db2e5c5ee03d0f801394abca205cd66f96c5be52 4ac75c5448f3d6d390648e0c03569d28e5e7eaae94504f77f8347d895fa1413d a02df234b2875a852281a245474be667b0df623a051d704d0c093b7356458381 4d01bbbcca523314949b488bcc65ede335bf0a5a805775b7169e1f919d91bf30 6cb78f50e4c773beffd1652c4bd0925459bd7c24a7a30004e27705750dc531c7 6cd9929bf14c925c3cbaa8cfd99e64e71c3ef5777ef033b8adb886012852f75b b720da914088e286b7893122018d2afd0d9b90fe4abf24e20e4e4004895b6def MITRE ATT&CK
Reporting
A widespread phishing campaign is compromising Microsoft 365 accounts with adversary-in-the-middle login pages that capture session material even when MFA is enabled, then using those identities to target payroll, HR, finance, and administrative staff across healthcare, education, manufacturing, government, and professional services in the United States, Canada, and Europe. Arctic Wolf said the activity aligns technically and behaviorally with Microsoft-tracked Storm-2755 (also known as Payroll Pirates), with attackers maintaining access through rotating residential proxies and automated session activity roughly every eight hours while quietly collecting mailbox data tied to financial workflows. Reporting also shows the intrusions can progress without additional device compromise, shifting instead into identity-plane lateral movement inside Entra ID and Microsoft 365. After an initial phish, attackers can use stolen session tokens to enumerate the tenant through Microsoft Graph, register a malicious Entra ID application, create a service principal, grant permissions such as Mail.Read and Mail.Send, and access other usersโ mailboxes, including executives, before sending fraudulent messages through Graph API that pass SPF and DKIM checks. Defenders were urged to correlate cloud identity, Graph, sign-in, and email telemetry for signals including OfficeHome error 90014, anomalous Outlook sign-ins with Firefox user agents, repeated SessionID reuse across changing IPs and geographies, suspicious app registrations, credential additions to service principals, and unusual application access to user mailboxes.
Attackers ran a procurement-themed adversary-in-the-middle phishing campaign against universities, enterprises, multinational institutions, and organizations linked to the European Union and United Nations, using compromised Outlook accounts to resend lures from trusted internal or partner addresses. Victims were directed to fake document download portals with CAPTCHA stages and cloned Microsoft 365 login pages impersonating brands including Microsoft, OpenGov, ConstructConnect, and the European Investment Bank, enabling the theft of credentials, session cookies, and MFA-authenticated tokens in real time. Researchers said the operation relied on reverse-proxy phishing kits including EvilProxy, FlowerStorm/Storm-1167, and Kali365 to bypass MFA and gain access to Outlook, SharePoint, and other Microsoft 365 resources. The infrastructure favored aged or compromised domains, RDGA-style phishing domains, phishing subdomain conventions, and injected PHP content on dormant websites, indicating an effort to evade detection by avoiding newly registered infrastructure; defenders were urged to use DNS and passive DNS visibility, Microsoft 365 sign-in monitoring, and conditional access controls because MFA alone does not stop session hijacking.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.