Storm-2657 is a financially motivated cybercrime threat actor associated with payroll-diversion fraud commonly described as “payroll pirate” activity. The actor is known for targeting employee identities and HR-related SaaS workflows, particularly in higher education in the United States, to redirect salary payments to attacker-controlled accounts. Microsoft has tracked this activity under the Storm-2657 designation, and reporting also associates the broader campaign branding “Payroll Pirates” with overlapping or related clusters including Storm-2755. Storm-2657 relies primarily on phishing for initial access, including adversary-in-the-middle techniques that capture credentials, MFA codes, and authenticated session material. The actor has used compromised organizational email accounts to distribute additional phishing messages at scale, tailoring lures to the recipient institution and using themes such as health alerts, misconduct notices, and HR or executive communications. The operation has targeted third-party HR and payroll platforms such as Workday through identity compromise rather than exploitation of a software vulnerability in those platforms. After compromising Microsoft 365 or Exchange Online accounts, Storm-2657 conducts post-compromise activity focused on payroll fraud. Observed behavior includes accessing employee HR profiles, modifying direct-deposit or payment-election settings, searching for payroll-, HR-, finance-, and administrative-related users and messages, and using Microsoft Graph for directory reconnaissance. The actor has also created inbox rules to suppress or delete warning notifications related to payroll or account changes, reducing the likelihood that victims detect unauthorized modifications. In some cases, the actor established persistence by enrolling attacker-controlled MFA devices or phone numbers in HR or federated authentication workflows. The actor’s tradecraft emphasizes stealth and cloud-native abuse over malware deployment. Reported activity includes session hijacking, repeated session refreshes through proxy-backed infrastructure, mailbox collection, and limited hands-on-keyboard actions designed to avoid noisy indicators such as password resets or broad lateral phishing in every case. Victimology directly supported at high confidence includes U.S. universities and broader U.S.-based organizations, with additional reporting linking related payroll-piracy activity to healthcare, manufacturing, and food services environments. The dominant objective is direct financial theft through payroll redirection rather than espionage or disruption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting adversary-in-the-middle phishing campaigns against Microsoft 365 users to hijack authenticated sessions, evade MFA, enumerate payroll/HR/finance personnel, and access payroll-related mailboxes to enable later financial fraud.
A related threat tracked by Microsoft since early 2025 in connection with similar financially motivated phishing and account-compromise activity.
Named phishing campaign targeting Microsoft 365 financial workflows.
Associated with the same payroll theft campaign involving AiTM phishing, Microsoft 365 account compromise, Graph API reconnaissance of payroll/HR personnel, and salary redirection fraud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.