Activity timeline
Storm-2755 appears in 3 tracked threats between and ; the busiest month was 2026-08 with 2 reports.
ATT&CK techniques observed
- T1078.004 Cloud Accounts — Persistenceobserved in 3 of 3 tracked threats
- T1114.002 Remote Email Collection — Collectionobserved in 3 of 3 tracked threats
- T1528 Steal Application Access Token — Credential Accessobserved in 3 of 3 tracked threats
- T1539 Steal Web Session Cookie — Credential Accessobserved in 3 of 3 tracked threats
- T1557 Adversary-in-the-Middle — Credential Accessobserved in 3 of 3 tracked threats
- T1564.008 Email Hiding Rules — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1566.002 Spearphishing Link — Initial Accessobserved in 3 of 3 tracked threats
- T1087.004 Cloud Account — Discoveryobserved in 2 of 3 tracked threats
- T1090.002 External Proxy — Command and Controlobserved in 2 of 3 tracked threats
- T1187 Forced Authentication — Credential Accessobserved in 2 of 3 tracked threats
- T1550.001 Application Access Token — Lateral Movementobserved in 2 of 3 tracked threats
- T1550.004 Web Session Cookie — Lateral Movementobserved in 2 of 3 tracked threats
- T1583.001 Domains — Resource Developmentobserved in 2 of 3 tracked threats
- T1583.008 Acquire Infrastructure: Malvertising — Resource Developmentobserved in 2 of 3 tracked threats
- T1608.006 SEO Poisoning — Resource Developmentobserved in 2 of 3 tracked threats
Tracked threats
- Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account CompromiseHIGH
- Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance EmailsHIGH
- Storm-2755 'Payroll Pirate' Campaign: AiTM Phishing and Workday Account Hijacking Targeting Canadian Employees (CVE-2025-27152)HIGH