Back to Intel

Intel Node

Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees

lowapt2026-04-09T15:00:00+00:00source excerpt
apttradecraftdetectionwindowsidentityemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Microsoft Incident Response – Detection and Response Team (DART) researchers observed an emerging, financially motivated threat actor, tracked as Storm-2755, compromising Canadian employee accounts to gain unauthorized access to employee profiles and divert salary payments to attacker-controlled accounts. The post Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees appeared first on Microsoft Security Blog .

In this article Storm-2755’s attack chain Defending against Storm-2755 and AiTM campaigns Microsoft Defender detection and hunting guidance Indicators of compromise Microsoft Incident Response – Detection and Response Team (DART) researchers observed an emerging, financially motivated threat actor that Microsoft tracks as Storm-2755 conducting payroll pirate attacks targeting Canadian users. In this campaign, Storm-2755 compromised user accounts to gain unauthorized access to employee profiles and divert salary payments to attacker-controlled accounts, resulting in direct financial loss for affected individuals and organizations.

While similar payroll pirate attacks have been observed in other malicious campaigns , Storm-2755’s campaign is distinct in both its delivery and targeting.

Read Original Source