Skip to content
← All Threat Actors
Cybercrime high Unknown

Storm-2755

Financially motivated criminal actor (Microsoft designation — origin not attributed) · Financial — payroll fraud via salary diversion to attacker-controlled bank accounts

Reports 1
Active Since 2026
Last Reported 15 Jul 2026
Sectors Targeted finance, professional-services, government, healthcare, communications

Tactics, Techniques & Procedures (TTPs)

  • Adversary-in-the-Middle (AiTM) phishing: reverse-proxy phishing pages capture username, password, and MFA-validated session tokens simultaneously as victim authenticates
  • MFA bypass via stolen session token: attacker presents a valid, MFA-verified session to HR/payroll portals — authentication event is legitimate and complete before interception
  • Multi-channel initial delivery: malvertising, SEO poisoning of HR-related search terms, and direct phishing email
  • CVE-2025-27152 (Axios SSRF) exploitation: server-side request forgery in Axios HTTP library used in some HR portal redirect flows to manipulate session handling
  • HR portal direct deposit modification: stolen session used to access payroll self-service and change employee bank account details to attacker-controlled accounts
  • Zero malware: no implants deployed at any stage — entire operation uses legitimate browser sessions with stolen tokens
  • Exclusively Canadian targeting: all confirmed victims are Canadian employees or Canadian-registered organisations

Known Targets

Canadian employees across sectors (healthcare, finance, government, professional services, communications)Organisations using cloud-based HR and payroll self-service portals (Workday, ADP, SAP SuccessFactors)Canadian public sector employees with direct deposit payroll systems

Analyst Notes

Disclosed by Microsoft in April 2026. Storm-2755's defining characteristic is a fully malware-free operational model: no implants, no C2 infrastructure, no endpoint security bypass required. The attack is entirely conducted through legitimate web browser sessions authenticated with stolen session tokens. From a security telemetry perspective, Storm-2755 intrusions are indistinguishable from an employee accessing their HR portal — which is exactly what is happening, with the wrong person authenticated. Detection is typically the next pay cycle when the victim notices their salary failed to arrive. The exclusively Canadian targeting suggests either deliberate avoidance of US law enforcement jurisdiction (US cyber fraud prosecutions are more aggressive) or specific familiarity with Canadian HR system architectures. The Axios SSRF (CVE-2025-27152) exploitation for session manipulation is technically sophisticated, indicating the group invests in specific technical capabilities alongside social engineering. Standard MFA enforcement does not protect against this attack — the MFA event completes legitimately before token capture.

Also Known As

Storm-2755 (Microsoft designation)"Payroll Pirate" (Microsoft informal descriptor)