# Storm-2755

> As of 2026-08-10, Storm-2755 is a N/A-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning phishing. Also known as Payroll Pirate. ATT&CK coverage spans 40 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1078.004 (Cloud Accounts), T1114.002 (Remote Email Collection), T1528 (Steal Application Access Token).

- **Nation:** N/A
- **Tracked threats:** 3
- **Categories:** PHISHING
- **Also known as:** Payroll Pirate
- **As of:** 2026-08-10

## ATT&CK techniques observed

40 techniques observed across 3 of 3 tracked threats. Tactics: Resource Development (7), Credential Access (6), Discovery (6), Persistence (5), Stealth (formerly Defense Evasion) (4), Command and Control (3).

- [T1078.004](https://intel.threadlinqs.com/technique/T1078.004) Cloud Accounts — Persistence — observed in 3 of 3 tracked threats
- [T1114.002](https://intel.threadlinqs.com/technique/T1114.002) Remote Email Collection — Collection — observed in 3 of 3 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 3 of 3 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 3 of 3 tracked threats
- [T1557](https://intel.threadlinqs.com/technique/T1557) Adversary-in-the-Middle — Credential Access — observed in 3 of 3 tracked threats
- [T1564.008](https://intel.threadlinqs.com/technique/T1564.008) Email Hiding Rules — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1566.002](https://intel.threadlinqs.com/technique/T1566.002) Spearphishing Link — Initial Access — observed in 3 of 3 tracked threats
- [T1087.004](https://intel.threadlinqs.com/technique/T1087.004) Cloud Account — Discovery — observed in 2 of 3 tracked threats
- [T1090.002](https://intel.threadlinqs.com/technique/T1090.002) External Proxy — Command and Control — observed in 2 of 3 tracked threats
- [T1187](https://intel.threadlinqs.com/technique/T1187) Forced Authentication — Credential Access — observed in 2 of 3 tracked threats
- [T1550.001](https://intel.threadlinqs.com/technique/T1550.001) Application Access Token — Lateral Movement — observed in 2 of 3 tracked threats
- [T1550.004](https://intel.threadlinqs.com/technique/T1550.004) Web Session Cookie — Lateral Movement — observed in 2 of 3 tracked threats
- [T1583.001](https://intel.threadlinqs.com/technique/T1583.001) Domains — Resource Development — observed in 2 of 3 tracked threats
- [T1583.008](https://intel.threadlinqs.com/technique/T1583.008) Acquire Infrastructure: Malvertising — Resource Development — observed in 2 of 3 tracked threats
- [T1608.006](https://intel.threadlinqs.com/technique/T1608.006) SEO Poisoning — Resource Development — observed in 2 of 3 tracked threats

## Tracked threats

- [Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise](https://intel.threadlinqs.com/threat/TL-2026-1970) — HIGH
- [Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance Emails](https://intel.threadlinqs.com/threat/TL-2026-1930) — HIGH
- [Storm-2755 'Payroll Pirate' Campaign: AiTM Phishing and Workday Account Hijacking Targeting Canadian Employees (CVE-2025-27152)](https://intel.threadlinqs.com/threat/TL-2026-0346) — HIGH

## Related CVEs

1 CVE referenced by tracked Storm-2755 activity.

- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Storm-2755
