Threadlinqs IntelligenceStart free

Threat actorN/ATracked since 2026-04

Storm-2755

Also known as:Payroll Pirate

As of 2026-08-10, Storm-2755 is a N/A-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning phishing. Also known as Payroll Pirate. ATT&CK coverage spans 40 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1078.004 (Cloud Accounts), T1114.002 (Remote Email Collection), T1528 (Steal Application Access Token).

Tracked threats
33 high
First seen
2026-04-10
Last seen
2026-08-10
ATT&CK techniques
40across 3 of 3 threats
Related CVEs
1Referenced by its activity
Attribution
N/ANation or origin
Nation: N/A · 3 tracked threat(s) · Categories: PHISHING

Activity timeline

Storm-2755 appears in 3 tracked threats between and ; the busiest month was 2026-08 with 2 reports.

ATT&CK techniques observed

40 techniques observed across 3 of 3 tracked threats · Resource Development (7), Credential Access (6), Discovery (6), Persistence (5), Stealth (formerly Defense Evasion) (4), Command and Control (3)
  • T1078.004 Cloud Accounts — Persistenceobserved in 3 of 3 tracked threats
  • T1114.002 Remote Email Collection — Collectionobserved in 3 of 3 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 3 of 3 tracked threats
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 3 of 3 tracked threats
  • T1557 Adversary-in-the-Middle — Credential Accessobserved in 3 of 3 tracked threats
  • T1564.008 Email Hiding Rules — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1566.002 Spearphishing Link — Initial Accessobserved in 3 of 3 tracked threats
  • T1087.004 Cloud Account — Discoveryobserved in 2 of 3 tracked threats
  • T1090.002 External Proxy — Command and Controlobserved in 2 of 3 tracked threats
  • T1187 Forced Authentication — Credential Accessobserved in 2 of 3 tracked threats
  • T1550.001 Application Access Token — Lateral Movementobserved in 2 of 3 tracked threats
  • T1550.004 Web Session Cookie — Lateral Movementobserved in 2 of 3 tracked threats
  • T1583.001 Domains — Resource Developmentobserved in 2 of 3 tracked threats
  • T1583.008 Acquire Infrastructure: Malvertising — Resource Developmentobserved in 2 of 3 tracked threats
  • T1608.006 SEO Poisoning — Resource Developmentobserved in 2 of 3 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Storm-2755 activity