Storm-2657 is a financially motivated threat actor targeting higher education institutions.
Analyst brief
Storm-2657 is a financially motivated threat actor targeting US-based organizations in higher education. They compromise employee accounts via phishing emails impersonating legitimate university communications and create inbox rules to delete HR platform (e.g., Workday) warnings. Key TTPs include account compromise, salary payment configuration manipulation, and redirecting funds to attacker-controlled accounts. Defenders should prioritize phishing-resistant MFA and monitor for suspicious inbox rules.
Storm-2657
unknown
Storm-2657 is a financially motivated threat actor targeting US-based organizations, particularly in higher education, to compromise employee accounts and redirect salary payments to attacker-controlled accounts. They employ tactics such as creating inbox rules to delete warning notifications from HR platforms like Workday and using phishing emails that impersonate legitimate university communications to gain access. The actor modifies employee salary payment configurations to facilitate financial theft. Mitigation efforts include implementing phishing-resistant MFA methods to secure user identities against such attacks.
How does Storm-2657 manipulate employee salary payments to conduct financial theft?+
After compromising employee accounts via phishing emails, Storm-2657 modifies salary payment configurations in HR platforms like Workday to redirect funds to attacker-controlled accounts.
What key technique does Storm-2657 use to avoid detection?+
The actor creates inbox rules to delete warning notifications from HR platforms, preventing the victim from becoming aware of suspicious transactions.