Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1167

Also known as: DEV-1167

Description

Storm-1167 is a threat actor tracked by Microsoft, known for their use of an AiTM phishing kit. They were responsible for launching an attack that led to Business Email Compromise activity.

AI Analysis

· 1 week ago

Executive Summary

Storm-1167, also known as DEV-1167, is a threat actor tracked by Microsoft for their use of an AiTM phishing kit. They are known to execute Business Email Compromise (BEC) activities, targeting corporate environments through sophisticated phishing campaigns. While their exact motivations and capabilities remain unclear due to limited publicly available information, their operations suggest a focus on financial gain and potential compromise of sensitive business data.

Goals & Targeting

Storm-1167's primary objectives appear to be financial gain through Business Email Compromise attacks. They target corporate environments across various industries but have demonstrated a particular interest in sectors where financial transactions are frequent and sensitive information is abundant. The group's targeting of multiple countries indicates a broad operational scope, potentially aiming to maximize their reach and potential victims. Their choice of phishing tools like the AiTM kit suggests an emphasis on scalability rather than precision, allowing them to compromise numerous victims efficiently.

Enhanced Description

Storm-1167 has been identified as a threat actor primarily active in the realm of cyberattacks that lead to Business Email Compromise (BEC). Microsoft's tracking efforts indicate that this group employs an AiTM phishing kit, which is typically utilized to send large volumes of malicious emails. These emails often contain links to fraudulent websites designed to steal credentials or distribute malware. The group's activities are indicative of a targeted approach towards corporate environments, where financial fraud and data exfiltration may be the primary objectives. Despite their operational presence, Storm-1167 remains a lesser-documented threat actor, with limited publicly available information on their exact modus operandi, sophistication level, and long-term strategic goals. Their use of specific phishing tools suggests a focus on efficiency and scalability in their attack campaigns.

Key Capabilities

  • Phishing campaign execution using AiTM phishing kits
  • Business Email Compromise (BEC) activities
  • Large-scale distribution of malicious emails
  • Potential use of compromised infrastructure for command and control

MITRE ATT&CK Tactics

Persistence
Credential Access
Exfiltration
Social Engineering

ATT&CK Techniques

T1566.003
T1566
T1254
T1333

Software / Tooling

AiTM Phishing Kit
Phishing as-a-Service Tools
Custom Malware for Credential Extraction

Campaigns & Victims

Storm-1167's campaign patterns include long-running and varied operational tempos, targeting multiple industries with phishing emails. Their campaigns often involve the use of disposable infrastructure to avoid detection. Notable past operations have resulted in significant financial losses through BEC activities. The group remains active but has not been extensively tracked due to their limited public exposure.

IOC Patterns

  • Spear-phishing emails containing malicious links
  • Phishing websites hosted on fast-flux domains
  • Bulk email distribution campaigns
  • Use of phishing kits for mass-scale attacks

Recommended Actions

  • Implement advanced email filtering solutions to detect and block phishing emails.
  • Conduct regular employee training on identifying suspicious emails and phishing attempts.
  • Monitor network traffic for signs of data exfiltration or malicious command-and-control communication.
  • Deploy multi-factor authentication (MFA) for sensitive accounts and financial transactions.
  • Review and update incident response plans to address potential BEC attacks.

Suggested Tags

APT
Phishing
Business Email Compromise
Financial Fraud
Corporate Espionage

Confidence Assessment

The confidence in Storm-1167's details is moderately low due to the limited availability of public information. While their involvement in BEC activities and use of phishing tools is well-documented, further intelligence on their strategic goals, geographic targeting scope, and specific TTPs would enhance understanding. There is a notable gap in reporting regarding their long-term objectives and potential affiliations with other threat groups.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
APT
Business Email Compromise
Financial Fraud
Corporate Espionage

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.