Threat hunters have discovered a new operation that targets employee mobile devices and facilitates payroll theft by using search engine optimization (SEO) poisoning techniques.
The behavior, which was initially discovered by ReliaQuest in May 2025 and targeted an unidentified manufacturing customer, is typified by the deployment of phony login pages to gain access to the employee payroll interface and divert wages into accounts controlled by the threat actor.
In an investigation released last week, the cybersecurity firm said that the attacker’s infrastructure evaded detection and slipped past conventional security measures by masking their traffic using hijacked home office routers and mobile networks.
The adversary used a phony website that mimicked the company’s login page to target staff mobile devices in particular read more about Employees Searching Payroll Portals on Google Tricked Into Sending Paychecks to Hackers.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
