Also known as: DEV-1167
Storm-1167 is a threat actor tracked by Microsoft, known for their use of an AiTM phishing kit. They were responsible for launching an attack that led to Business Email Compromise activity.
Executive Summary
Storm-1167, also known as DEV-1167, is a threat actor tracked by Microsoft for their use of an AiTM phishing kit. They are known to execute Business Email Compromise (BEC) activities, targeting corporate environments through sophisticated phishing campaigns. While their exact motivations and capabilities remain unclear due to limited publicly available information, their operations suggest a focus on financial gain and potential compromise of sensitive business data.
Goals & Targeting
Storm-1167's primary objectives appear to be financial gain through Business Email Compromise attacks. They target corporate environments across various industries but have demonstrated a particular interest in sectors where financial transactions are frequent and sensitive information is abundant. The group's targeting of multiple countries indicates a broad operational scope, potentially aiming to maximize their reach and potential victims. Their choice of phishing tools like the AiTM kit suggests an emphasis on scalability rather than precision, allowing them to compromise numerous victims efficiently.
Enhanced Description
Storm-1167 has been identified as a threat actor primarily active in the realm of cyberattacks that lead to Business Email Compromise (BEC). Microsoft's tracking efforts indicate that this group employs an AiTM phishing kit, which is typically utilized to send large volumes of malicious emails. These emails often contain links to fraudulent websites designed to steal credentials or distribute malware. The group's activities are indicative of a targeted approach towards corporate environments, where financial fraud and data exfiltration may be the primary objectives. Despite their operational presence, Storm-1167 remains a lesser-documented threat actor, with limited publicly available information on their exact modus operandi, sophistication level, and long-term strategic goals. Their use of specific phishing tools suggests a focus on efficiency and scalability in their attack campaigns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-1167's campaign patterns include long-running and varied operational tempos, targeting multiple industries with phishing emails. Their campaigns often involve the use of disposable infrastructure to avoid detection. Notable past operations have resulted in significant financial losses through BEC activities. The group remains active but has not been extensively tracked due to their limited public exposure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in Storm-1167's details is moderately low due to the limited availability of public information. While their involvement in BEC activities and use of phishing tools is well-documented, further intelligence on their strategic goals, geographic targeting scope, and specific TTPs would enhance understanding. There is a notable gap in reporting regarding their long-term objectives and potential affiliations with other threat groups.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics