Storm-2755 is a financially motivated cybercriminal threat actor tracked by Microsoft and associated with payroll-diversion or "payroll pirate" operations. The group has been observed targeting Canadian users and organizations in multiple sectors, including healthcare, manufacturing, and food services, with the objective of redirecting employee salary payments to attacker-controlled bank accounts. Storm-2755 commonly gains initial access through adversary-in-the-middle phishing that captures authenticated Microsoft 365 sessions. Reported delivery methods include SEO poisoning and malvertising that steer victims to convincing fake Microsoft 365 sign-in pages. By proxying the authentication flow in real time, the actor steals credentials, session cookies, and OAuth access tokens, enabling session hijacking and bypass of non-phishing-resistant MFA. After account compromise, Storm-2755 conducts cloud-based reconnaissance focused on payroll, HR, finance, administrative, and related roles. The actor has used Microsoft Graph API queries to enumerate directory users and identify personnel relevant to payroll processing. Post-compromise activity includes searching victim mailboxes for payroll-related content, impersonating employees in messages to HR or finance, and sending direct-deposit change requests. To conceal the fraud, the actor has created inbox rules that hide responses related to banking or direct-deposit changes. In some cases, when email-based social engineering was insufficient, Storm-2755 directly accessed HR SaaS platforms such as Workday using stolen sessions and manually altered payroll details. The group’s operations are notable for relying on legitimate cloud services and stolen sessions rather than malware or software exploitation on endpoints, leaving minimal endpoint telemetry. Observed persistence-related behavior has included repeated non-interactive cloud sign-ins to maintain session access, as well as occasional password and MFA-setting changes to retain control beyond the lifetime of stolen tokens. Storm-2755 has also been linked in reporting to activity clusters alongside Storm-2657, another payroll-theft-focused cluster, but Storm-2755 itself is best characterized as a cloud-centric, financially motivated actor specializing in AiTM-enabled account takeover, session hijacking, reconnaissance, and payroll fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for other adversary-in-the-middle session hijacking attacks leading to SaaS account takeover.
Conducting account takeover and payroll diversion operations by using adversary-in-the-middle phishing to steal Microsoft 365 session tokens, bypass MFA, enumerate payroll/HR staff via Microsoft Graph API, and redirect employee direct deposits.
Associated with the Payroll Pirate campaign targeting corporate finance, HR, payroll, and administrative personnel to steal employee salary payments through account manipulation.
Conducting payroll diversion attacks against Canadian users by stealing Microsoft 365 credentials and session tokens, then socially engineering HR or finance staff to change direct deposit information to attacker-controlled bank accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.