Hackers Hijack Paychecks by Tricking Employees with Fake Payroll Portals in Google Search Results


# SEO Poisoning Campaign Targets Mobile Devices for Payroll Fraud

Security researchers at ReliaQuest have uncovered a sophisticated campaign using SEO poisoning techniques to target employees’ mobile devices and facilitate payroll fraud. First detected in May 2025 affecting a manufacturing sector company, the attack uses fake login pages to access payroll portals and redirect paychecks to attacker-controlled accounts.

## How the Attack Works

The attack begins when employees search for their company’s payroll portal on search engines. Deceptive lookalike websites appear at the top of search results through sponsored links. When clicked, these links lead to WordPress sites that redirect mobile users to phishing pages mimicking Microsoft login portals.

Once credentials are entered, they are immediately exfiltrated to attacker-controlled servers. The system establishes a WebSocket connection that alerts attackers via Pusher’s push notification API, allowing them to use the stolen credentials before they can be changed.

## Strategic Targeting of Mobile Devices

The attackers specifically target mobile devices for two key advantages:
– Mobile devices typically lack enterprise-grade security measures
– Connections occur outside corporate networks, reducing visibility and complicating investigations

## Evasion Techniques

To avoid detection, attackers route login attempts through:
– Compromised home office routers (ASUS, Pakedge)
– Residential IP addresses
– Mobile networks

These compromised devices are enlisted into proxy botnets and rented to cybercriminals, allowing attacks to appear to originate from legitimate locations.

## Related Phishing Campaigns

The report coincides with discoveries of other sophisticated phishing operations:

1. **Adobe Shared File Impersonation**: Hunt.io identified a campaign using fake Adobe Shared File pages to steal Microsoft Outlook credentials using the W3LL phishing kit.

2. **CoGUI Phishing Kit**: Targeting Japanese organizations by impersonating brands like Amazon, PayPay, and Apple. Over 580 million emails were sent between January-April 2025 using this kit, which employs geofencing and fingerprinting to evade detection.

3. **Panda Shop**: A new customizable smishing kit from Chinese cybercrime networks using Telegram channels and bots to automate service delivery. It’s connected to underground carding shops where stolen data is sold to other criminals.

Security researchers note that Chinese cybercriminal syndicates behind these operations operate with relative impunity, feeling protected from U.S. law enforcement while residing in China.

Share This Article