Storm-2755 Payroll Pirate Attacks: How Cybercriminals Hijack Salaries Through Session Theft

Listen to this Post

Featured Image

Introduction: A New Wave of Financially Driven Cyberattacks

Cybercriminal activity continues to evolve beyond traditional data theft, increasingly targeting direct financial gain through sophisticated identity-based attacks. One of the latest examples comes from Microsoft’s Incident Response team, which uncovered a campaign led by a threat actor known as Storm-2755. This group has introduced a dangerous twist to account compromise by redirecting employee salaries into attacker-controlled accounts.

Unlike broad ransomware campaigns or data breaches, this operation is precise, silent, and financially devastating. By exploiting authentication systems and user behavior, Storm-2755 demonstrates how modern attackers blend into legitimate workflows, making detection significantly harder.

Summary of the Attack Campaign

Storm-2755 executed a highly targeted campaign focused primarily on users in Canada, leveraging search engine manipulation and deceptive online advertising to lure victims. Instead of targeting specific industries, the attackers relied on geographic filtering combined with common search queries such as “Office 365” or even misspelled variations like “Office 265.” These tactics ensured a wide but region-specific victim pool.

Users who clicked on malicious links were redirected to a fake Microsoft 365 login page designed to closely mimic the real authentication interface. Once credentials were entered, the attackers captured not only usernames and passwords but also authentication tokens using adversary-in-the-middle techniques. This allowed them to bypass traditional multi-factor authentication protections and gain full access to user sessions.

After initial access, Storm-2755 maintained persistence by replaying stolen session tokens. These sessions appeared legitimate, often using tools like Axios to interact with Microsoft services. The attackers ensured continuous access by refreshing sessions approximately every 30 minutes, effectively blending their activity with normal user behavior.

With access secured, the attackers began reconnaissance. They searched internal systems for payroll-related information using keywords such as “HR,” “finance,” and “direct deposit.” This step was critical in identifying opportunities to manipulate salary payments.

To execute their financial objective, Storm-2755 used two main strategies. In some cases, they impersonated employees by sending emails to HR departments requesting updates to direct deposit information. In other instances, they directly accessed HR software platforms like Workday and manually altered banking details.

To avoid detection, the attackers created email rules that automatically filtered messages containing sensitive keywords like “bank” or “direct deposit” into hidden folders. This prevented victims from noticing suspicious communication from HR teams. Additionally, they operated during off-hours, typically around 5:00 AM, reducing the likelihood of triggering alerts or user intervention.

The end result was direct financial theft. In at least one confirmed case, a victim’s salary was successfully redirected to an attacker-controlled account, highlighting the real-world impact of these attacks.

Microsoft responded by assisting affected organizations, revoking compromised sessions, and sharing detailed threat intelligence. The company also emphasized the importance of phishing-resistant authentication methods and improved monitoring systems to counter such threats.

What Undercode Say:

The Shift Toward Identity-Centric Attacks

Storm-2755 represents a broader industry trend where attackers prioritize identity over infrastructure. Instead of breaking systems, they log in as legitimate users. This reduces noise, avoids triggering traditional security alerts, and allows attackers to operate within trusted environments.

AiTM Attacks Are the Real Game Changer

Adversary-in-the-middle techniques redefine phishing. Traditional phishing steals credentials, but AiTM steals sessions. This distinction is critical because session tokens grant immediate authenticated access, effectively rendering many MFA implementations useless unless they are phishing-resistant.

MFA Is No Longer a Silver Bullet

The campaign highlights a harsh reality: not all MFA is equal. SMS codes, push notifications, and email-based verification can be intercepted or bypassed. Only modern methods like FIDO2 or WebAuthN provide meaningful resistance against these attacks.

Living Off the Land Strategy

Storm-2755 avoids deploying malware. Instead, they use legitimate tools, services, and workflows. This “living off the land” approach minimizes forensic evidence and complicates detection efforts.

Timing as a Stealth Mechanism

Operating during early morning hours is not random. It reflects a calculated decision to reduce interference from users and administrators. This behavioral pattern is increasingly common in advanced persistent threats.

Email Manipulation as a Defense Evasion Technique

Creating inbox rules to hide critical emails is a simple yet highly effective tactic. It turns the victim into an unaware participant, allowing attackers to carry out actions without raising suspicion.

SaaS Platforms as High-Value Targets

The pivot to platforms like Workday reveals a growing attack surface. As organizations migrate to cloud-based HR and finance systems, attackers follow. These platforms hold direct pathways to financial assets, making them prime targets.

Token Persistence: The Silent Threat

Even without credentials, attackers maintained access for extended periods using stolen tokens. This shows how session management policies can become a critical weak point if not properly enforced.

Detection Requires Behavioral Analysis

Signature-based detection is ineffective against such attacks. Organizations must adopt behavioral analytics to identify anomalies like unusual login times, unfamiliar user agents, and abnormal access patterns.

Security Is Now a Continuous Process

Static defenses are no longer sufficient. Continuous access evaluation, real-time token revocation, and adaptive authentication policies are essential to staying ahead of attackers like Storm-2755.

Fact Checker Results

✅ Storm-2755 used adversary-in-the-middle techniques to hijack authenticated sessions and bypass traditional MFA.
✅ The campaign relied heavily on SEO poisoning and malvertising to lure victims into fake login pages.
❌ The attack did not depend on malware deployment; instead, it abused legitimate services and workflows.

Prediction

🔮 Identity-based attacks will continue to replace traditional malware-driven campaigns as the primary threat vector.
🔮 Organizations will accelerate adoption of phishing-resistant authentication methods such as FIDO2.
🔮 SaaS platforms handling financial operations will become the next major battleground for cybercriminal activity.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.microsoft.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon