Also known as: DEV-0867
Storm-0867 is a threat actor that has been active since 2012 and has targeted various industries and regions. They employ sophisticated phishing campaigns, utilizing social engineering techniques and a phishing as a service platform called Caffeine. Their attacks involve intercepting and manipulating communication between users and legitimate services, allowing them to steal passwords, hijack sign-in sessions, bypass multifactor authentication, and modify authentication methods.
Executive Summary
Storm-0867, also known as DEV-0867, is a sophisticated cyber threat actor active since 2012, primarily targeting multiple industries and regions through advanced phishing campaigns and social engineering techniques. The group utilizes a phishing-as-a-service platform called Caffeine to intercept and manipulate user communications, enabling credential theft, MFA bypass, and unauthorized access.
Goals & Targeting
Storm-0867's strategic objectives likely include espionage, financial gain, or disrupting targeted organizations. The actor's choice of victims spans multiple industries, indicating a broad targeting strategy without sector-specific preference. Their geographic reach across regions implies a global focus, with no apparent restriction to specific countries. Typical victims are organizations with significant digital assets, sensitive data, or strong authentication mechanisms that the group aims to bypass.
Enhanced Description
Storm-0867 is a cyber threat actor that has been operational since 2012, with a primary focus on conducting sophisticated phishing campaigns. The group employs social engineering techniques and leverages a platform named Caffeine, described as a phishing-as-a-service (PhaaS) tool. This platform facilitates the interception and manipulation of communications between users and legitimate services, allowing the actors to steal sensitive information such as passwords and authentication tokens. Storm-0867 is known for targeting various industries and regions, though specific sectors and countries remain undefined in available intelligence. The group has demonstrated advanced capabilities in bypassing multifactor authentication (MFA) and modifying authentication methods, indicating a high level of technical expertise. Their operations suggest a focus on infiltrating secure environments to achieve long-term access or data exfiltration.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-0867 has conducted long-term campaigns since 2012, indicating a patient and methodical approach. Their operations typically involve targeted phishing attacks against organizations to harvest credentials and circumvent security measures. The group's use of a dedicated PhaaS platform suggests an organized operational model, enabling efficient attack planning and execution. Campaign patterns include continuous evolution of tactics to avoid detection and maintain persistence in target networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
This assessment is based on moderate confidence in available data. While specific details about the group's primary motivation, exact targeted sectors, and precise geographic focus are unclear, there is sufficient information to outline their capabilities, tactics, and operational patterns. Further intelligence collection is needed to fill gaps in understanding their strategic objectives and campaign specifics.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics