Storm-2657 is a threat actor tracked by Microsoft, associated with phishing campaigns targeting Microsoft 365 accounts. Documented since early 2025, it shares tactical overlaps with Storm-2755 and is involved in credential theft and financial email collection.