Phase Details Threat Actor Storm-2657, a financially motivated group. Targets U.S.-based organizations, with a particular focus on employees in higher education. Initial Access The actor typically uses phishing emails to steal credentials and Multi-Factor Authentication (MFA) codes using Adversary-in-the-Middle (AiTM) phishing links. In other cases, they targeted accounts without MFA enabled. Compromise They gained unauthorized access to the victims' Exchange Online email accounts and then hijacked and modified their Workday (a common HR/payroll SaaS platform) profiles via Single Sign-On (SSO). Defense Evasion The actor created inbox rules on the victim's email account. The rules were designed to automatically delete or hide incoming warning notification emails from Workday about the payroll changes. Impact/Objective The actor modified the employee's salary payment configuration in their HR profile, specifically changing the direct deposit/bank account details to an account under the actor's control. Persistence In observed cases, the threat actor established persistence by enrolling their own phone numbers as MFA devices for victim accounts, bypassing the need for the legitimate user's future approval.
Published by Banx Network. This article is part of the Banx decentralized media programme, powered by the BXE token on the XRP Ledger.




