Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0867

Also known as: DEV-0867

Description

Storm-0867 is a threat actor that has been active since 2012 and has targeted various industries and regions. They employ sophisticated phishing campaigns, utilizing social engineering techniques and a phishing as a service platform called Caffeine. Their attacks involve intercepting and manipulating communication between users and legitimate services, allowing them to steal passwords, hijack sign-in sessions, bypass multifactor authentication, and modify authentication methods.

AI Analysis

· 1 week ago

Executive Summary

Storm-0867, also known as DEV-0867, is a sophisticated cyber threat actor active since 2012, primarily targeting multiple industries and regions through advanced phishing campaigns and social engineering techniques. The group utilizes a phishing-as-a-service platform called Caffeine to intercept and manipulate user communications, enabling credential theft, MFA bypass, and unauthorized access.

Goals & Targeting

Storm-0867's strategic objectives likely include espionage, financial gain, or disrupting targeted organizations. The actor's choice of victims spans multiple industries, indicating a broad targeting strategy without sector-specific preference. Their geographic reach across regions implies a global focus, with no apparent restriction to specific countries. Typical victims are organizations with significant digital assets, sensitive data, or strong authentication mechanisms that the group aims to bypass.

Enhanced Description

Storm-0867 is a cyber threat actor that has been operational since 2012, with a primary focus on conducting sophisticated phishing campaigns. The group employs social engineering techniques and leverages a platform named Caffeine, described as a phishing-as-a-service (PhaaS) tool. This platform facilitates the interception and manipulation of communications between users and legitimate services, allowing the actors to steal sensitive information such as passwords and authentication tokens. Storm-0867 is known for targeting various industries and regions, though specific sectors and countries remain undefined in available intelligence. The group has demonstrated advanced capabilities in bypassing multifactor authentication (MFA) and modifying authentication methods, indicating a high level of technical expertise. Their operations suggest a focus on infiltrating secure environments to achieve long-term access or data exfiltration.

Key Capabilities

  • Sophisticated phishing campaigns
  • Social engineering techniques
  • Phishing-as-a-service (Caffeine platform)
  • Credential harvesting via intercepted communications
  • Bypass of multifactor authentication (MFA)
  • Modification of authentication methods

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access

ATT&CK Techniques

T1059.003 - Remote Access Tools: Custom Tools
T1078 - Phishing
T1091 - Office Document Malware
T1566.001 - Credentials from Browser

Software / Tooling

Caffeine (PhaaS platform)
Custom phishing tools
Social engineering kits

Campaigns & Victims

Storm-0867 has conducted long-term campaigns since 2012, indicating a patient and methodical approach. Their operations typically involve targeted phishing attacks against organizations to harvest credentials and circumvent security measures. The group's use of a dedicated PhaaS platform suggests an organized operational model, enabling efficient attack planning and execution. Campaign patterns include continuous evolution of tactics to avoid detection and maintain persistence in target networks.

IOC Patterns

  • Phishing emails with malicious links or attachments
  • Intercepted authentication sessions via communication interception
  • Use of Caffeine PhaaS platform for phishing campaigns
  • Manipulation of legitimate service communication flows

Recommended Actions

  • Implement and enforce multifactor authentication (MFA) across all critical systems.
  • Conduct regular user training on recognizing phishing attempts and suspicious activities.
  • Monitor network traffic for signs of intercepted or manipulated communications.
  • Deploy endpoint detection and response (EDR) solutions to detect malicious activity.
  • Perform periodic threat hunting exercises focusing on phishing-related IOC patterns.

Suggested Tags

APT
Phishing
Cyber Espionage
Social Engineering

Confidence Assessment

This assessment is based on moderate confidence in available data. While specific details about the group's primary motivation, exact targeted sectors, and precise geographic focus are unclear, there is sufficient information to outline their capabilities, tactics, and operational patterns. Further intelligence collection is needed to fill gaps in understanding their strategic objectives and campaign specifics.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
APT
Cyber Espionage
Social Engineering

Details

Type
Unknown
Country of Origin
E
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.