Storm-2657, also referred to as Payroll Pirates, is a financially motivated cybercrime threat actor focused on payroll-diversion fraud. The group targets employee identities and HR-related SaaS workflows rather than exploiting software vulnerabilities in payroll platforms themselves. Its operations have been observed primarily against U.S.-based organizations, with a strong emphasis on higher education, and related reporting also links the cluster to activity affecting healthcare, manufacturing, and food services environments. Storm-2657 commonly gains initial access through phishing, including adversary-in-the-middle techniques designed to capture credentials, MFA codes, or authenticated cloud sessions. The actor has used compromised organizational email accounts to distribute additional phishing messages at scale, tailoring lures to institutional context. After compromising Microsoft 365 or Exchange Online accounts, the group conducts post-compromise reconnaissance for payroll, HR, finance, and administrative functions, including use of Microsoft Graph API queries to enumerate relevant users and collect mailbox data. A defining objective of Storm-2657 activity is unauthorized modification of payroll or direct-deposit settings in HR platforms such as Workday so that salary payments are redirected to attacker-controlled accounts. To conceal these changes, the actor creates inbox rules that delete, hide, or divert HR and payroll notifications. Observed persistence methods include session reuse, session hijacking, and enrollment of attacker-controlled MFA devices or phone numbers in victim profiles. In some related campaigns, the actor maintained access through repeated cloud sign-ins via proxy infrastructure while minimizing noisy follow-on actions. The group’s tradecraft is consistent with business email compromise-style financial theft adapted to cloud identity systems and HR workflows. Reported behaviors include phishing, session hijacking, credential theft, reconnaissance, persistence, defense evasion through inbox-rule abuse and stealthy cloud access, and exfiltration of payroll- and finance-related mailbox content. Microsoft has also linked Storm-2657 with broader payroll-pirate activity clusters alongside Storm-2755, though Storm-2657 is specifically associated with campaigns targeting university employees and payroll systems beginning in 2025.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related threat tracked by Microsoft since early 2025 in connection with similar financially motivated phishing and account-compromise activity.
Associated with the same payroll theft campaign involving AiTM phishing, Microsoft 365 account compromise, Graph API reconnaissance of payroll/HR personnel, and salary redirection fraud.
Associated with the Payroll Pirate campaign targeting corporate finance, HR, payroll, and administrative personnel to steal employee salary payments through account manipulation.
Conducted a payroll diversion campaign targeting U.S. university employees' Workday accounts, using phishing and AiTM tactics to steal MFA codes and compromise Exchange Online accounts in order to hijack salary payments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.