RCFH AiTM toolkit — redirector & proxy root domains (Payroll Pirates / Storm-2755)
Adversary-in-the-middle credential/session theft feeding payroll-diversion BEC, overlapping the cluster Microsoft tracks as Storm-2755. Chain: voicemail-themed mail with subject '[Organization] :ATTN: Review messages. Ref id: [random]' -> redirect laundered through Google Meet linkredirect, Google Ads /ddm/clk/ click trackers and an S3 intermediary -> an 'idp.'-labelled Apache redirector 302s to the AiTM proxy -> the proxy bounces the victim once to /st_58200519/class_identifier.php to fingerprint the browser and cache a country code in an rcfh_country cookie -> the proxy relays the genuine login.microsoftonline.com flow, rewriting Microsoft's endpoints into its own path, and captures the authorization code and ID token at its callback. Post-compromise the actor signs in from residential proxies on an eight-hour cadence keeping one SessionID across ASNs, enumerates payroll/HR/finance staff over Microsoft Graph with an axios/1.18.1 user agent, and reads mail on payroll, invoices, banking and benefits.
Anchors
domain:*keyreniao.com OR domain:*korminel.com OR domain:*kualabemo.com OR domain:*camberwolis.com OR domain:*milocaroline.com OR domain:*monlinelogicaline.com OR domain:*logicalineonline.com OR domain:*offirmtm.com OR domain:*oficarine.com OR domain:*ofrecie.com OR domain:*ofreace.com OR domain:*ofreice.com OR domain:*ofrecre.com OR domain:*ofercarc.com OR domain:*ocrifere.com OR domain:*ocifire.comProvenance
Sightings (0)
No sightings recorded yet.