Storm-2755
Financially motivated criminal actor (Microsoft designation — origin not attributed) · Financial — payroll fraud via salary diversion to attacker-controlled bank accounts
Tactics, Techniques & Procedures (TTPs)
- Adversary-in-the-Middle (AiTM) phishing: reverse-proxy phishing pages capture username, password, and MFA-validated session tokens simultaneously as victim authenticates
- MFA bypass via stolen session token: attacker presents a valid, MFA-verified session to HR/payroll portals — authentication event is legitimate and complete before interception
- Multi-channel initial delivery: malvertising, SEO poisoning of HR-related search terms, and direct phishing email
- CVE-2025-27152 (Axios SSRF) exploitation: server-side request forgery in Axios HTTP library used in some HR portal redirect flows to manipulate session handling
- HR portal direct deposit modification: stolen session used to access payroll self-service and change employee bank account details to attacker-controlled accounts
- Zero malware: no implants deployed at any stage — entire operation uses legitimate browser sessions with stolen tokens
- Exclusively Canadian targeting: all confirmed victims are Canadian employees or Canadian-registered organisations
Known Targets
Analyst Notes
Disclosed by Microsoft in April 2026. Storm-2755's defining characteristic is a fully malware-free operational model: no implants, no C2 infrastructure, no endpoint security bypass required. The attack is entirely conducted through legitimate web browser sessions authenticated with stolen session tokens. From a security telemetry perspective, Storm-2755 intrusions are indistinguishable from an employee accessing their HR portal — which is exactly what is happening, with the wrong person authenticated. Detection is typically the next pay cycle when the victim notices their salary failed to arrive. The exclusively Canadian targeting suggests either deliberate avoidance of US law enforcement jurisdiction (US cyber fraud prosecutions are more aggressive) or specific familiarity with Canadian HR system architectures. The Axios SSRF (CVE-2025-27152) exploitation for session manipulation is technically sophisticated, indicating the group invests in specific technical capabilities alongside social engineering. Standard MFA enforcement does not protect against this attack — the MFA event completes legitimately before token capture.
Also Known As
MITRE ATT&CK Techniques