Also known as: tracked as
Storm‑2755 operates a large‑scale phishing operation that leverages voicemail‑themed emails to lure victims into malicious Microsoft 365 login pages. Victims are redirected through legitimate services to an adversary‑in‑the‑middle (AiTM) proxy, allowing the actor to intercept authentication tokens even when multi‑factor authentication is enabled. Once authenticated, attackers employ residential proxies and perform automated sign‑ins every eight hours, collecting e‑mail communications from employees involved in financial workflows. The threat actor uses Microsoft Graph for reconnaissance of payroll, HR and finance users, then coordinates mailbox collection before manipulating SaaS payroll settings. The campaign shares characteristics with Microsoft’s Tracked Storm‑2755 activity cluster, operating across a broad range of sectors—healthcare, education, manufacturing, government, defense, non‑profit, retail, think‑tanks and media—in the United States, Canada, Ireland, Russia, North Korea and India. Its blend of BEC, token hijacking, MFA bypass and SaaS manipulation demonstrates a high level of operational sophistication.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑2755 is a financially motivated threat actor targeting Microsoft 365 users via sophisticated phishing and adversary‐in‐the‐middle techniques. The campaign focuses on payroll, HR and finance personnel across sectors in the United States, Canada, and parts of Europe, using stolen sessions to bypass MFA and alter direct deposit information.
Goals & Targeting
The actor’s strategic objective is financial gain through payroll fraud and direct deposit diversion. By targeting organizations with complex Microsoft 365 environments, Storm‑2755 exploits the dependency on cloud services for payroll processing. The use of geographic filtering (e.g., Canadian users) suggests a focus on jurisdictions where regulatory scrutiny may be lower or where victims are more likely to fall for social engineering. Overall, its profile aligns with financially driven, credential‑based threat actors that prioritize high‑value payroll targets.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑2755 exhibits a disciplined operational tempo, with repeated automated sign‑ins at regular intervals and the use of residential proxies to maintain persistence. The actor specifically targets payroll, HR and finance users across a wide geographical footprint—primarily North America but also parts of Europe—indicating an opportunistic selection of organizations with high-value financial processes. Its techniques mirror those observed in other Microsoft‑tracked phishing clusters, suggesting either collaboration or shared methodology within the broader adversary ecosystem.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a coherent picture of Storm‑2755’s financial objectives, sector focus and technical tactics. Confidence is high regarding the phishing vector, token hijacking and payroll manipulation activities, yet significant gaps remain in defining the actor’s organisational affiliation, precise geographic scope beyond Canada and the United States, and lifecycle timeline (first-see/last-see). Further intelligence collection on attribution and broader geopolitical context would strengthen actionable insights.
No campaigns linked yet.
No observed data linked yet.
27
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics