A sophisticated cyberattack campaign leveraging search engine optimization (SEO) poisoning techniques has been uncovered, enabling threat actors to divert employee payroll payments by hijacking authentication credentials.
ReliaQuest identified this novel attack chain that specifically targets the payroll processes of enterprises, with a recent case impacting a manufacturing sector client and exposing significant security gaps in how organizations manage off-network device authentication.
Technical Overview
In this campaign, adversaries deploy highly engineered fake login portals that mimic legitimate organizational web pages.

By manipulating mobile-device-specific ad settings, these malicious websites appear at the top of search results when employees search for payroll or HR portal access on their phones.
Employees accessing these sites often outside corporate networks and security controls unknowingly input their credentials into phishing pages.
When credentials are entered, the phishing page sends an HTTP POST request to an attacker-controlled PHP endpoint.
Simultaneously, a WebSocket connection is established with ws-ap2.pusher[.]com using the attacker’s Pusher application key, offering the threat actor real-time notification of compromised accounts.
This innovative abuse of the legitimate Pusher messaging platform allows attackers to promptly harvest credentials and rapidly use them to access payroll systems before defensive actions can be taken.

Proxy Network Evasion
The campaign’s focus on mobile devices poses a unique challenge for security teams.
Mobile endpoints, frequently disconnected from secure Wi-Fi or corporate networks and lacking enterprise-grade monitoring, become a blind spot for detection tools.
Furthermore, because these attacks often occur outside standard working hours and networks, incident response and forensics are significantly hindered.
After harvesting credentials, the attacker logs into the organization’s payroll portal, often SAP SuccessFactors, from a series of obfuscated residential IP addresses.
Analysis revealed that many of these IPs originate from consumer routers such as ASUS and Pakedge compromised via default credentials or unpatched vulnerabilities (e.g., CVE-2024-3080, CVE-2025-2492).
These infected routers are then utilized as proxies, making attacker traffic indistinguishable from legitimate user activity and undermining IP-based geolocation or blacklisting defenses.
Upon successful access, the adversary alters direct deposit settings in payroll systems, funneling wages to attacker-controlled accounts.
The use of residential proxies and dynamic IPs acquired from commercial proxy botnet services allows sustained access and camouflages malicious behavior, complicating forensic investigations and response.
The financial impact is substantial, with risks including direct monetary loss, erosion of employee trust, payroll disruptions, and regulatory penalties for mishandling personal and financial data.
To mitigate the risk from such advanced campaigns, security teams are urged to enforce multifactor authentication (MFA) for payroll systems, establish out-of-band alerts for direct deposit changes, and invest in digital risk protection services to rapidly detect domain impersonation.
Employee awareness campaigns and strict guidance to access payroll portals via bookmarked URLs or SSO should complement technical controls.
Additionally, advanced monitoring should be implemented for anomalous access patterns, especially those emanating from suspicious residential networks.
This campaign marks a dangerous evolution in payroll fraud, combining social engineering, real-time credential theft, and proxy-based evasion.
Organizations must reassess their off-network security posture, especially regarding mobile device access to sensitive portals, and align policies to counter these emerging TTPs.
A zero-trust approach, robust user education, and rapid threat intelligence ingestion are essential to prevent similar incidents.
Indicators of Compromise (IOC)
| Artifact | Details/Notes |
|---|---|
| 188.143.232[.]224 | Attacker IP sourcing from Russia |
| 2600:387:f:5610[::]a | Attacker mobile provider IPv6 address |
| 2600:387:15:4f15[::]4 | Attacker mobile provider IPv6 address |
| 2600:387:f:7911[::]6 | Attacker mobile provider IPv6 address |
| 2600:387:15:4f10[::]7 | Attacker mobile provider IPv6 address |
| 24.35.218[.]249 | Residential proxy IP |
| 45.25.222[.]95 | Residential proxy IP |
| 47.147.0[.]43 | Residential proxy IP |
| 67.248.0[.]40 | Residential proxy IP |
| 70.184.85[.]12 | Residential proxy IP |
| 71.204.101[.]149 | Residential proxy IP |
| 72.85.59[.]141 | Residential proxy IP |
| 74.135.76[.]49 | Residential proxy IP |
| 75.69.94[.]63 | Residential proxy IP |
| 75.113.173[.]76 | Residential proxy IP |
| 76.181.194[.]172 | Residential proxy IP |
| 98.144.134[.]107 | Residential proxy IP |
| 104.237.113[.]2 | Residential proxy IP |
| 107.115.239[.]26 | Residential proxy IP |
| 107.116.79[.]10 | Residential proxy IP |
| 136.41.4[.]175 | Residential proxy IP |
| 142.196.199[.]253 | Residential proxy IP |
| 172.223.158[.]102 | Residential proxy IP |
| 173.209.172[.]26 | Residential proxy IP |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates