Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors storm-2755

Also known as: tracked as

Description

Storm‑2755 operates a large‑scale phishing operation that leverages voicemail‑themed emails to lure victims into malicious Microsoft 365 login pages. Victims are redirected through legitimate services to an adversary‑in‑the‑middle (AiTM) proxy, allowing the actor to intercept authentication tokens even when multi‑factor authentication is enabled. Once authenticated, attackers employ residential proxies and perform automated sign‑ins every eight hours, collecting e‑mail communications from employees involved in financial workflows. The threat actor uses Microsoft Graph for reconnaissance of payroll, HR and finance users, then coordinates mailbox collection before manipulating SaaS payroll settings. The campaign shares characteristics with Microsoft’s Tracked Storm‑2755 activity cluster, operating across a broad range of sectors—healthcare, education, manufacturing, government, defense, non‑profit, retail, think‑tanks and media—in the United States, Canada, Ireland, Russia, North Korea and India. Its blend of BEC, token hijacking, MFA bypass and SaaS manipulation demonstrates a high level of operational sophistication.

Goals & Targeting

Targeted Sectors

Healthcare
Education
Manufacturing
Government
Financial services
Defense
Non profit
Retail
Think tank
Media

Targeted Countries / Regions

United States of America
Canada
CA
US
IL
RU
KP
IN

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 3 days ago

Executive Summary

Storm‑2755 is a financially motivated threat actor targeting Microsoft 365 users via sophisticated phishing and adversary‐in‐the‐middle techniques. The campaign focuses on payroll, HR and finance personnel across sectors in the United States, Canada, and parts of Europe, using stolen sessions to bypass MFA and alter direct deposit information.

Goals & Targeting

The actor’s strategic objective is financial gain through payroll fraud and direct deposit diversion. By targeting organizations with complex Microsoft 365 environments, Storm‑2755 exploits the dependency on cloud services for payroll processing. The use of geographic filtering (e.g., Canadian users) suggests a focus on jurisdictions where regulatory scrutiny may be lower or where victims are more likely to fall for social engineering. Overall, its profile aligns with financially driven, credential‑based threat actors that prioritize high‑value payroll targets.

Enhanced Description

Key Capabilities

  • Credential harvesting via malicious login page
  • Adversary-in-the-middle session hijacking using stolen tokens
  • Token replay for persistence without MFA prompts
  • Social engineering emails to manipulate payroll instructions
  • Geographic filtering targeting Canadian users
  • SEO poisoning and malvertising delivery of phishing pages
  • Email inbox rule creation for message suppression
  • Session renewal outside business hours to avoid detection
  • Manual modification of SaaS payroll information

MITRE ATT&CK Tactics

Initial Access
Valid Accounts
Credential Access
Persistence
Defense Evasion
Impact

ATT&CK Techniques

T1566.001
T1078

Software / Tooling

Axios HTTP Client

Campaigns & Victims

Storm‑2755 exhibits a disciplined operational tempo, with repeated automated sign‑ins at regular intervals and the use of residential proxies to maintain persistence. The actor specifically targets payroll, HR and finance users across a wide geographical footprint—primarily North America but also parts of Europe—indicating an opportunistic selection of organizations with high-value financial processes. Its techniques mirror those observed in other Microsoft‑tracked phishing clusters, suggesting either collaboration or shared methodology within the broader adversary ecosystem.

IOC Patterns

  • Session cookie theft and replay
  • MFA bypass through authentication token reuse
  • Malicious sign-in page mimicking Microsoft 365
  • Non-interactive OfficeHome sign-ins every ~30 minutes
  • Creation of inbox rules that move emails containing keywords 'direct deposit' or 'bank' to hidden folder
  • Automatic session renewal around 5:00 AM to prevent re‑authentication during business hours

Recommended Actions

  • Implement phishing-resistant MFA such as FIDO2/WebAuthN and block legacy authentication protocols
  • Revoke active or anomalous session tokens to terminate hijacked sessions promptly
  • Investigate suspicious non-interactive sign-ins, especially those occurring outside business hours
  • Mitigate malvertising and SEO poisoning by filtering search results and blocking known malicious domains
  • Train users on recognizing direct deposit email spoofing and payroll manipulation scams
  • Enforce device compliance through Conditional Access policies
  • Deploy SIEM monitoring with baselines to detect anomalous activity patterns
  • Configure Microsoft Defender to automatically disrupt suspected attacks and revoke tokens in real time
  • Audit OAuth third-party applications to prevent persistence via integrated services
  • Run regular phishing simulation campaigns to maintain user awareness

Suggested Tags

Payroll Fraud
Canada Targeting
AiTM
Malvertising
SEO Poisoning
Token Hijacking
MFA Bypass
Social Engineering Email
BEC
Workday
SaaS
Financial exploitation

Confidence Assessment

The available data provides a coherent picture of Storm‑2755’s financial objectives, sector focus and technical tactics. Confidence is high regarding the phishing vector, token hijacking and payroll manipulation activities, yet significant gaps remain in defining the actor’s organisational affiliation, precise geographic scope beyond Canada and the United States, and lifecycle timeline (first-see/last-see). Further intelligence collection on attribution and broader geopolitical context would strengthen actionable insights.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. mallory.ai — Cited by web research for: T1078
  2. attack.mitre.org — Cited by web research for: Interception
  3. www.microsoft.com — Cited by web research for: Microsoft Defender XDR
  4. learn.microsoft.com — Cited by web research for: Tsunami
  5. www.ncei.noaa.gov — Cited by web research for: LANDFALL
  6. www.microsoft.com — Cited by web research for: StilachiRAT
  7. https://pushsecurity.com/blog/phishing-with-active-directory-federation-services/ — Cited by AI analysis.

Intel Summary

27

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Payroll Fraud
Canada Targeting
AiTM
Malvertising
SEO Poisoning
Token Hijacking
MFA Bypass
Social Engineering Email
BEC
Workday
SaaS
Financial exploitation

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.