Also known as: DEV-1101
DEV-1101 is a threat actor tracked by Microsoft who is responsible for developing and advertising phishing kits, specifically AiTM phishing kits. These kits are capable of bypassing multifactor authentication and are available for purchase or rent by other cybercriminals. DEV-1101 offers an open-source kit with various enhancements, such as mobile device management and CAPTCHA evasion. Their tool has been used in high-volume phishing campaigns by multiple actors, including DEV-0928, and is sold for $300 with VIP licenses available for $1,000.
Executive Summary
Storm-1101, also known as DEV-1101, is a threat actor associated with Microsoft, specializing in the development and distribution of phishing kits that bypass multifactor authentication (MFA). These kits have been used by other actors, such as DEV-0928, and are available for purchase or rental, including an open-source version with advanced features like mobile device management and CAPTCHA evasion. Storm-1101's activities pose significant risks to organizations due to their ability to facilitate large-scale phishing campaigns.
Goals & Targeting
Storm-1101 appears to be motivated primarily by financial gain, targeting sectors where high-value assets or sensitive data can be exploited. This likely includes industries such as finance, healthcare, and technology, where phishing campaigns can yield significant returns. The actor's victims are typically organizations with vulnerabilities in email security, MFA implementations, or user training. Their approach to selling kits suggests a focus on maximizing reach rather than selecting specific high-profile targets.
Enhanced Description
Storm-1101 operates as a cybercriminal developer, focusing on creating sophisticated phishing tools designed to circumvent MFA protection mechanisms. The actor offers an open-source phishing kit that includes advanced capabilities such as mobile device management and techniques to evade CAPTCHA challenges. These kits are sold or rented, with premium VIP licenses available for higher costs. The actor's toolset has been utilized in high-volume phishing campaigns by other cybercriminal groups, highlighting the threat posed by commoditized attack tools. Storm-1101's business model allows even less sophisticated actors to carry out complex attacks, increasing the potential impact of their operations on targeted organizations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-1101's campaigns are characterized by their scalability and adaptability, as the phishing kits can be customized for various attack vectors. The actor has been linked to multiple high-profile campaigns, particularly in sectors with weak email security posture. The use of rental models allows the actor to maintain operational distance from direct campaign activities, making attribution challenging.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the identification of Storm-1101 as a developer and seller of phishing kits is high, based on Microsoft's reporting. However, specific targeting patterns or victimology beyond the known campaigns may not be fully understood due to the commoditized nature of these tools.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics