Also known as: tracked as
Storm‑2657, also known as the Payroll Pirate, emerged in mid‑2025 targeting U.S. organizations with a focus on higher education but extending into finance, defense, government, healthcare and non‑profit sectors. The actor conducts tailored spearphishing campaigns that mimic legitimate university communications to lure staff, often employing adversary‑in‑the‑middle links to harvest MFA codes. Once account access is secured—typically via compromised Exchange Online credentials—the threat team gains SSO entry to Workday, modifies payroll configuration files, and redirects salary deposits to attacker-controlled accounts. Persistent tactics include creating invisible inbox rules that delete or hide HR notifications, enrolling the actors’ own phone numbers as MFA devices, and leveraging social engineering to bypass organizational controls. Operationally, Storm‑2657 seems to time attacks around payroll processing windows, exploiting the absence of strong MFA on SaaS platforms rather than platform vulnerabilities. Their methodology combines classic credential theft with sophisticated post‑exploitation techniques that hide changes in HR data while maintaining legitimate user access to facilitate a prolonged presence.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑2657 is a financially motivated threat actor that has carried out sophisticated phishing and adversary‑in‑the‑middle campaigns to compromise employee accounts in U.S. higher‑education institutions, subsequently hijacking Workday payroll systems to redirect salaries. The group relies heavily on email rule manipulation, MFA credential harvesting, and SSO exploitation for persistence and stealth. Mitigation requires enforcing passwordless MFA, vigilant monitoring of HR platform changes, and comprehensive phishing awareness training.
Goals & Targeting
The actor’s strategic objective is direct financial gain through payroll hijacking, focusing on U.S. higher‑education institutions where salary payments occur in large, predictable batches. By leveraging phishing and MFA bypasses, Storm‑2657 seeks low‑effort, high‑return operations that minimize detection risk. While the primary target set includes universities, the threat actor also expands to sectors with centralized payroll systems such as finance, defense, government and healthcare, indicating a broader opportunistic profile beyond purely academic institutions.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑2657’s campaigns appear to have started in mid‑2025 with a clear operational tempo centered on payroll processing periods. Their methodology is consistent: use phishing and MFA bypasses, gain SSO access to Workday via compromised Exchange accounts, modify payroll configurations, and conceal activity through inbox rule manipulation. Victim profiles include U.S. universities, finance, defense, government agencies, healthcare providers, non‑profits and news/media organizations—any entity with a centralized payroll system and reliance on SaaS HR platforms. The actor’s recent operations have not involved platform exploitation or zero‑day vulnerabilities, indicating a preference for social engineering over technical weaknesses.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Evidence from multiple reputable sources confirms Storm‑2657’s use of phishing and MFA bypass to hijack Workday payroll for financial gain. The consistency of their tactics across several higher‑education victims provides high confidence in the described capabilities and objectives. However, gaps remain regarding the actor’s full range of toolsets beyond the identified malware families, long‑term operational scope outside the U.S., and detailed timelines for first/last seen activities.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
42
Tools
0
Campaigns
33
IOCs
0
Observed Data
3
Tactics