Storm-1167 logo

Storm-1167

0 incidentes 0 paises 0 sectores apt ID Ultimo: -
Aliases: DEV-1167
Ver en IntelTracker → APTTrail →
Storm-1167 is a threat actor first publicly documented by Microsoft in June 2023, known for orchestrating multi-stage Adversary-in-the-Middle (AiTM) phishing and Business Email Compromise (BEC) campaigns primarily aimed at financial gain, though initial tracking by Microsoft is for emerging clusters until higher confidence about their full scope or state-sponsorship is reached. This group distinguishes itself through its unique use of an indirect proxy AiTM phishing kit, enabling flexible tailoring of spoofed login pages and effective bypass of multi-factor authentication (MFA) by capturing session cookies. The group has been observed adding new MFA methods to compromised accounts for persistence and launching large-scale secondary phishing campaigns from victim mailboxes. Storm-1167 is also tracked under the alias DEV-1167.
Tecnicas MITRE
T1059.001, T1203, T1071.001, T1566.001

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
apt
Pais origen
ID
Motivacion
-
Impacto
3
Actualizado
Sat, 03 Fe

Sectores objetivo (SOCRadar)

FinanceBankingManagement, Scientific, and Technical Consulting ServicesComputer Systems Design and Related Services