Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1295

Also known as: DEV-1295

Description

Storm-1295 is a threat actor group that operates the Greatness phishing-as-a-service platform. They utilize synchronous relay servers to present targets with a replica of a sign-in page, resembling traditional phishing attacks. Their adversary-in-the-middle capability allows Storm-1295 to offer their services to other attackers. Active since mid-2022, Storm-1295 is tracked by Microsoft and is known for their involvement in the Greatness PhaaS platform.

AI Analysis

· 1 week ago

Executive Summary

Storm-1295, also known as DEV-1295, is a threat actor group operating since mid-2022 that provides phishing-as-a-service through the Greatness platform. They specialize in creating replica sign-in pages using synchronous relay servers to steal credentials and offer their services to other attackers. Their activities are tracked by Microsoft, highlighting their potential impact on various sectors.

Goals & Targeting

Storm-1295 primarily targets sectors with valuable data or financial interests due to the nature of their phishing campaigns. Their strategic objective appears to be profit-driven, catering to other attackers by providing ready-to-use phishing tools. This makes them a significant threat to organizations across various industries, as they can facilitate large-scale credential theft and potential ransomware deployments.

Enhanced Description

Storm-1295 is a notable threat actor group primarily known for their Phishing-as-a-Service (PhaaS) platform called Greatness. They leverage sophisticated techniques to mimic legitimate sign-in pages, enabling them to steal sensitive information from victims. Their operations involve creating replica login interfaces that are effectively indistinguishable from genuine ones, making their phishing campaigns highly successful. Storm-1295's adversary-in-the-middle capability allows them to offer their services to other cybercriminals, expanding their reach and impact in the threat landscape.

Key Capabilities

  • Phishing-as-a-Service platform (Greatness)
  • Synchronous relay servers for creating replica sign-in pages
  • Credential harvesting through phishing techniques

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Defense Evasion

ATT&CK Techniques

T1566.002
T1689.001
T1078.001

Software / Tooling

Greatness PhaaS Platform
Synchronous relay server software
Phishing email templates

Campaigns & Victims

Storm-1295's campaigns typically involve mass phishing attempts, leveraging their platform to distribute malicious links and payloads. Their operational tempo is moderate but effective due to their service-based model. Microsoft tracking indicates they have been active since mid-2022, with notable campaigns including those targeting financial institutions and healthcare sectors.

IOC Patterns

  • Phishing emails mimicking login pages
  • Malicious domains used in phishing campaigns
  • Spear-phishing with custom URLs leading to credential theft

Recommended Actions

  • Enhance email filtering to detect malicious links
  • Conduct regular user training on phishing awareness
  • Monitor for domain name system (DNS) tunneling activities
  • Implement multi-factor authentication (MFA)
  • Regularly update and patch software vulnerabilities

Suggested Tags

Phishing-As-A-Service
Cybercrime Infrastructure
Credential Thefts
Financial Fraud

Confidence Assessment

Moderate confidence in the data with significant gaps in specific campaigns and exact targeting sectors. Additional information regarding their operational TTPs and tools would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Phishing-As-A-Service
Cybercrime Infrastructure
Credential Thefts
Financial Fraud

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.