Also known as: DEV-1295
Storm-1295 is a threat actor group that operates the Greatness phishing-as-a-service platform. They utilize synchronous relay servers to present targets with a replica of a sign-in page, resembling traditional phishing attacks. Their adversary-in-the-middle capability allows Storm-1295 to offer their services to other attackers. Active since mid-2022, Storm-1295 is tracked by Microsoft and is known for their involvement in the Greatness PhaaS platform.
Executive Summary
Storm-1295, also known as DEV-1295, is a threat actor group operating since mid-2022 that provides phishing-as-a-service through the Greatness platform. They specialize in creating replica sign-in pages using synchronous relay servers to steal credentials and offer their services to other attackers. Their activities are tracked by Microsoft, highlighting their potential impact on various sectors.
Goals & Targeting
Storm-1295 primarily targets sectors with valuable data or financial interests due to the nature of their phishing campaigns. Their strategic objective appears to be profit-driven, catering to other attackers by providing ready-to-use phishing tools. This makes them a significant threat to organizations across various industries, as they can facilitate large-scale credential theft and potential ransomware deployments.
Enhanced Description
Storm-1295 is a notable threat actor group primarily known for their Phishing-as-a-Service (PhaaS) platform called Greatness. They leverage sophisticated techniques to mimic legitimate sign-in pages, enabling them to steal sensitive information from victims. Their operations involve creating replica login interfaces that are effectively indistinguishable from genuine ones, making their phishing campaigns highly successful. Storm-1295's adversary-in-the-middle capability allows them to offer their services to other cybercriminals, expanding their reach and impact in the threat landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-1295's campaigns typically involve mass phishing attempts, leveraging their platform to distribute malicious links and payloads. Their operational tempo is moderate but effective due to their service-based model. Microsoft tracking indicates they have been active since mid-2022, with notable campaigns including those targeting financial institutions and healthcare sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the data with significant gaps in specific campaigns and exact targeting sectors. Additional information regarding their operational TTPs and tools would enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics