Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1101

Also known as: DEV-1101

Description

DEV-1101 is a threat actor tracked by Microsoft who is responsible for developing and advertising phishing kits, specifically AiTM phishing kits. These kits are capable of bypassing multifactor authentication and are available for purchase or rent by other cybercriminals. DEV-1101 offers an open-source kit with various enhancements, such as mobile device management and CAPTCHA evasion. Their tool has been used in high-volume phishing campaigns by multiple actors, including DEV-0928, and is sold for $300 with VIP licenses available for $1,000.

AI Analysis

· 1 week ago

Executive Summary

Storm-1101, also known as DEV-1101, is a threat actor associated with Microsoft, specializing in the development and distribution of phishing kits that bypass multifactor authentication (MFA). These kits have been used by other actors, such as DEV-0928, and are available for purchase or rental, including an open-source version with advanced features like mobile device management and CAPTCHA evasion. Storm-1101's activities pose significant risks to organizations due to their ability to facilitate large-scale phishing campaigns.

Goals & Targeting

Storm-1101 appears to be motivated primarily by financial gain, targeting sectors where high-value assets or sensitive data can be exploited. This likely includes industries such as finance, healthcare, and technology, where phishing campaigns can yield significant returns. The actor's victims are typically organizations with vulnerabilities in email security, MFA implementations, or user training. Their approach to selling kits suggests a focus on maximizing reach rather than selecting specific high-profile targets.

Enhanced Description

Storm-1101 operates as a cybercriminal developer, focusing on creating sophisticated phishing tools designed to circumvent MFA protection mechanisms. The actor offers an open-source phishing kit that includes advanced capabilities such as mobile device management and techniques to evade CAPTCHA challenges. These kits are sold or rented, with premium VIP licenses available for higher costs. The actor's toolset has been utilized in high-volume phishing campaigns by other cybercriminal groups, highlighting the threat posed by commoditized attack tools. Storm-1101's business model allows even less sophisticated actors to carry out complex attacks, increasing the potential impact of their operations on targeted organizations.

Key Capabilities

  • Development and distribution of phishing kits capable of bypassing MFA
  • Sophisticated features such as mobile device management and CAPTCHA evasion
  • Open-source kit with rental and premium VIP license options
  • High-volume phishing campaign capabilities

MITRE ATT&CK Tactics

Espionage
Impact

ATT&CK Techniques

T1566.001
T1059.003

Software / Tooling

Storm-1101 Phishing Kit

Campaigns & Victims

Storm-1101's campaigns are characterized by their scalability and adaptability, as the phishing kits can be customized for various attack vectors. The actor has been linked to multiple high-profile campaigns, particularly in sectors with weak email security posture. The use of rental models allows the actor to maintain operational distance from direct campaign activities, making attribution challenging.

IOC Patterns

  • Spear-phishing emails targeting users with access to sensitive systems
  • Use of macro-laced Office documents for payload delivery
  • C2 communication via compromised domains using fast-flux networks

Recommended Actions

  • Enhance MFA implementations beyond the phishing-bypass capabilities of available kits
  • Monitor for indicators associated with known phishing campaigns linked to Storm-1101
  • Educate users on recognizing and reporting suspicious emails
  • Implement email filtering solutions to block phishing attempts

Suggested Tags

APT
cybercrime

Confidence Assessment

Confidence in the identification of Storm-1101 as a developer and seller of phishing kits is high, based on Microsoft's reporting. However, specific targeting patterns or victimology beyond the known campaigns may not be fully understood due to the commoditized nature of these tools.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
APT
cybercrime

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.