Storm-2755 is a financially motivated cybercrime threat actor tracked by Microsoft and associated with "Payroll Pirate" operations focused on payroll diversion and related business email compromise activity. The group is known for adversary-in-the-middle phishing against Microsoft 365 users, using SEO poisoning, malvertising, and phishing lures to capture credentials, session cookies, and OAuth tokens from live authentication flows and thereby bypass non-phishing-resistant MFA. Victimology includes Canadian users prominently, with broader overlap observed in campaigns affecting organizations in the United States and Europe across healthcare, manufacturing, food services, education, government, and professional services. After obtaining access, Storm-2755 abuses authenticated cloud sessions rather than relying on malware on endpoints. The actor has been observed maintaining stolen sessions through recurring non-interactive sign-ins and rotating proxy infrastructure, including residential proxies selected to match victim geography. Post-compromise activity includes mailbox searches and Microsoft Graph API reconnaissance to identify payroll, HR, finance, and administrative personnel, followed by collection of messages related to payroll, invoices, payments, banking, benefits, and internal documents. In some intrusions the actor created inbox rules to hide responses related to payroll changes. The actor’s primary objective is direct financial theft through fraudulent direct-deposit changes. Storm-2755 has impersonated employees in emails to HR or finance staff requesting payroll updates and, in some cases, directly accessed HR SaaS platforms such as Workday to alter banking details. The cluster has also been linked to quieter session-hijacking campaigns that emphasize reconnaissance, mailbox collection, and stealthy persistence while avoiding more conspicuous actions such as broad lateral phishing or overt tenant modification. Storm-2755 has notable tactical overlap with the related Microsoft-tracked cluster Storm-2657.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
32 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A financially motivated threat cluster associated with payroll diversion attacks that hijack employee accounts to reroute salary payments to attacker-controlled accounts.
Email-driven AiTM phishing campaign targeting Microsoft 365 accounts to compromise users, identify personnel involved in payroll, HR, finance, and administrative workflows, maintain stolen sessions via rotating residential proxies, and collect related mailbox data.
Referenced as a comparison point for other adversary-in-the-middle session hijacking attacks leading to SaaS account takeover.
Conducting account takeover and payroll diversion operations by using adversary-in-the-middle phishing to steal Microsoft 365 session tokens, bypass MFA, enumerate payroll/HR staff via Microsoft Graph API, and redirect employee direct deposits.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.