Microsoft Threat Intelligence Podcast

Ahoy! A Tale of Payroll Pirates Who Target Universities


Listen Later

In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by security researchers Tori Murphy and Anna Seitz to unpack two financially motivated cyber threats. First, they explore the Payroll Pirates campaign (Storm 2657), which targets university payroll systems through phishing and MFA theft to reroute direct deposits. Then, they examine Vanilla Tempest, a ransomware group abusing fraudulent Microsoft Teams installers and SEO poisoning to deliver the Oyster Backdoor and Recita ransomware.  

Together, they discuss how attackers exploit trust in identity, code signing, and SaaS platforms and share practical steps organizations can take to strengthen defenses, from phishing-resistant MFA to stricter executable controls and out-of-band banking verification. 


In this episode you’ll learn:      

  • How Payroll Pirates diverted university salaries through SaaS HR phishing schemes 

    • Why universities are prime targets for identity-based cyberattacks 

      • How Vanilla Tempest evolved from basic ransomware to complex multi-stage attacks 

        Some questions we ask:     

        • How are attackers stealing credentials and paychecks? 

          • Why do attackers create inbox rules after compromising accounts? 

            • What alerts should organizations monitor for these types of attacks? 


              Resources:  

              • View Tori Murphy on LinkedIn  

                • View Anna Seitz on LinkedIn 

                  • View Sherrod DeGrippo on LinkedIn  


                    Investigating targeted “payroll pirate” attacks affecting US universities 

                    Microsoft Threat Intelligence healthcare ransomware report highlights need for collective industry action 

                     

                    Related Microsoft Podcasts:                   

                    • Afternoon Cyber Tea with Ann Johnson 

                      • The BlueHat Podcast 

                        • Uncovering Hidden Risks     

                           

                          Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                           

                          Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                           

                          The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network. 

                          ...more
                          View all episodesView all episodes
                          Download on the App Store

                          Microsoft Threat Intelligence PodcastBy Microsoft

                          • 5
                          • 5
                          • 5
                          • 5
                          • 5

                          5

                          22 ratings


                          More shows like Microsoft Threat Intelligence Podcast

                          View all
                          Hacked by Hacked

                          Hacked

                          187 Listeners

                          Security Now (Audio) by TWiT

                          Security Now (Audio)

                          2,006 Listeners

                          The Talk Show With John Gruber by Daring Fireball / John Gruber

                          The Talk Show With John Gruber

                          3,143 Listeners

                          Risky Business by Patrick Gray

                          Risky Business

                          372 Listeners

                          SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

                          SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

                          651 Listeners

                          CyberWire Daily by N2K Networks

                          CyberWire Daily

                          1,020 Listeners

                          Smashing Security by Graham Cluley

                          Smashing Security

                          319 Listeners

                          Click Here by Recorded Future News

                          Click Here

                          416 Listeners

                          Darknet Diaries by Jack Rhysider

                          Darknet Diaries

                          8,057 Listeners

                          Cybersecurity Today by Jim Love

                          Cybersecurity Today

                          179 Listeners

                          Hacking Humans by N2K Networks

                          Hacking Humans

                          315 Listeners

                          CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                          CISO Series Podcast

                          188 Listeners

                          Cybersecurity Headlines by CISO Series

                          Cybersecurity Headlines

                          139 Listeners

                          Cyber Hack by BBC World Service

                          Cyber Hack

                          1,607 Listeners

                          Risky Bulletin by risky.biz

                          Risky Bulletin

                          44 Listeners