Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-2657

Also known as: tracked as

Description

Storm‑2657, also known as the Payroll Pirate, emerged in mid‑2025 targeting U.S. organizations with a focus on higher education but extending into finance, defense, government, healthcare and non‑profit sectors. The actor conducts tailored spearphishing campaigns that mimic legitimate university communications to lure staff, often employing adversary‑in‑the‑middle links to harvest MFA codes. Once account access is secured—typically via compromised Exchange Online credentials—the threat team gains SSO entry to Workday, modifies payroll configuration files, and redirects salary deposits to attacker-controlled accounts. Persistent tactics include creating invisible inbox rules that delete or hide HR notifications, enrolling the actors’ own phone numbers as MFA devices, and leveraging social engineering to bypass organizational controls. Operationally, Storm‑2657 seems to time attacks around payroll processing windows, exploiting the absence of strong MFA on SaaS platforms rather than platform vulnerabilities. Their methodology combines classic credential theft with sophisticated post‑exploitation techniques that hide changes in HR data while maintaining legitimate user access to facilitate a prolonged presence.

Goals & Targeting

Targeted Sectors

Education
Financial services
Defense
Government
Non profit
Healthcare
Think tank
Media

Targeted Countries / Regions

US
IL
RU
KP
IN

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 7 hours ago

Executive Summary

Storm‑2657 is a financially motivated threat actor that has carried out sophisticated phishing and adversary‑in‑the‑middle campaigns to compromise employee accounts in U.S. higher‑education institutions, subsequently hijacking Workday payroll systems to redirect salaries. The group relies heavily on email rule manipulation, MFA credential harvesting, and SSO exploitation for persistence and stealth. Mitigation requires enforcing passwordless MFA, vigilant monitoring of HR platform changes, and comprehensive phishing awareness training.

Goals & Targeting

The actor’s strategic objective is direct financial gain through payroll hijacking, focusing on U.S. higher‑education institutions where salary payments occur in large, predictable batches. By leveraging phishing and MFA bypasses, Storm‑2657 seeks low‑effort, high‑return operations that minimize detection risk. While the primary target set includes universities, the threat actor also expands to sectors with centralized payroll systems such as finance, defense, government and healthcare, indicating a broader opportunistic profile beyond purely academic institutions.

Enhanced Description

Key Capabilities

  • Sophisticated phishing campaigns including adversary‑in‑the‑middle links to harvest credentials and MFA codes
  • Compromise of employee accounts on HR SaaS platforms (e.g., Workday) via SSO and Exchange Online exploitation
  • Hijacking payroll systems by modifying HR payroll data to redirect salary payments
  • Creation of email inbox rules that delete or hide notification emails for stealth
  • Enrollment of attacker-controlled phone numbers as MFA devices for persistence

MITRE ATT&CK Tactics

Initial Access
Credential Access
Persistence
Defense Evasion
Impact

ATT&CK Techniques

T1566.001
T1078
T1181

Software / Tooling

SUNBURST
gh0st RAT
ClickFix
Imperial Kitten
SolarWinds
Mythic

Campaigns & Victims

Storm‑2657’s campaigns appear to have started in mid‑2025 with a clear operational tempo centered on payroll processing periods. Their methodology is consistent: use phishing and MFA bypasses, gain SSO access to Workday via compromised Exchange accounts, modify payroll configurations, and conceal activity through inbox rule manipulation. Victim profiles include U.S. universities, finance, defense, government agencies, healthcare providers, non‑profits and news/media organizations—any entity with a centralized payroll system and reliance on SaaS HR platforms. The actor’s recent operations have not involved platform exploitation or zero‑day vulnerabilities, indicating a preference for social engineering over technical weaknesses.

IOC Patterns

  • Phishing emails targeting HR personnel
  • Spearphishing links or attachments used to obtain credentials
  • Adversary‑in‑the‑middle links harvesting MFA codes
  • Account takeover indicators such as unauthorized session activity
  • Suspicious inbox rule creation with special characters
  • Use of attacker‑controlled domains in phishing URLs

Recommended Actions

  • Enforce strong, passwordless MFA (e.g., FIDO2 security keys, Windows Hello for Business, passkeys) across all SaaS HR platforms and email accounts
  • Provide targeted security awareness training focused on spearphishing, social engineering, and adversary‐in‑the‑middle attacks
  • Monitor employee account activity during salary processing windows for anomalous logins or privilege escalations
  • Implement vendor guidance to detect and remediate payroll hijack changes in Workday
  • Enable detection queries and hunting alerts for suspicious inbox rule creation and HR platform modifications
  • Continuously audit Exchange Online, Office 365, and Workday access logs for unauthorized or unusual activity

Suggested Tags

FinancialMotivation
PayrollHijack
SaaSTargeting
Workday
HigherEducation
AccountTakeover
SocialEngineering
AcademicTargeting
University
Phishing
SpearphishingLink
AdversaryInTheMiddle
MFABypass
MFAEnrollment
PasswordlessDefense

Confidence Assessment

Evidence from multiple reputable sources confirms Storm‑2657’s use of phishing and MFA bypass to hijack Workday payroll for financial gain. The consistency of their tactics across several higher‑education victims provides high confidence in the described capabilities and objectives. However, gaps remain regarding the actor’s full range of toolsets beyond the identified malware families, long‑term operational scope outside the U.S., and detailed timelines for first/last seen activities.

ATT&CK Techniques

Initial Access
1 technique
Stealth
1 technique
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 20

References

  1. www.microsoft.com — Cited by web research for: Microsoft Defender XDR
  2. learn.microsoft.com — Cited by web research for: Tsunami
  3. www.microsoft.com — Cited by web research for: AADInternals
  4. https://malpedia.caad.fkie.fraunhofer.de/actor/storm-2657 — Cited by AI analysis.
  5. https://www.safestate.com/post/payroll-pirates-workday-direct-deposit-attack — Cited by AI analysis.
  6. https://www.mitiga.io/videos/payroll-pirates-workday-direct-deposit-attack — Cited by AI analysis.

Intel Summary

3

Techniques

42

Tools

0

Campaigns

33

IOCs

0

Observed Data

3

Tactics

Tags

Critical Infrastructure
Phishing
Financially motivated
APT
Higher Education
Fraud
US-based Threat Actor
FinancialMotivation
PayrollHijack
SaaSTargeting
Workday
HigherEducation
AccountTakeover
SocialEngineering
AcademicTargeting
University
SpearphishingLink
AdversaryInTheMiddle
MFABypass
MFAEnrollment
PasswordlessDefense

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.