Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)

PremiumReviewedSigma · High · v1
Product
m365
Service
exchange
Author
HuntRule
Published
2026-08-04
Updated
2026-08-28

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation or modification of Exchange Online inbox rules that filter messages from myworkday.com and delete or move them to obscure folders. This behavior is associated with payroll pirate campaigns against US universities where attackers hide Workday payroll and direct deposit change notifications from compromised victims. Concealing these alerts lets attackers reroute salary payments without the victim noticing, making early detection critical.

Related detections8 linkedT1114.003 — drag to rearrange
Malicious Mailbox Forwarding Rule Creation (via exchange)
Malicious Office 365 Email Forwarding Rule to External Domain (via office365)
Google Workspace login activity: Out-of-domain email forwarding
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Azure Risk Event: Suspicious Inbox Forwarding
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Pivot detection · T1114.003 · 8 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.