Storm-1152, a cybercriminal group, was recently taken down by Microsoft for illegally reselling Outlook accounts. They operated by creating approximately 750 million fraudulent Microsoft accounts and earned millions of dollars in illicit revenue. Storm-1152 also offered CAPTCHA-solving services and was connected to ransomware and extortion groups. Microsoft obtained a court order to seize their infrastructure and domains, disrupting their operations.
Executive Summary
Storm-1152 is a cybercriminal group primarily engaged in fraudulent activities, including the creation of millions of illegal Microsoft accounts and offering CAPTCHA-solving services. Associated with ransomware and extortion operations, they were successfully disrupted by Microsoft through legal action, though their full capabilities and threat trajectory remain partially understood.
Goals & Targeting
Storm-1152's primary goals appear to be financial gain through the sale of fraudulent accounts and the provision of services that enable other cybercriminal activities. Their targeting focuses on creating and monetizing large volumes of illegal Microsoft accounts, which can be used for various malicious purposes such as phishing,诈骗, and unauthorized access. The group likely targets sectors with high reliance on digital communication and online services, potentially including industries like technology, healthcare, and education, where the possession of legitimate-seeming accounts could provide significant value. Their association with ransomware groups suggests an interest in supporting broader extortion campaigns.
Enhanced Description
Storm-1152 operates as a cybercriminal group specializing in the creation of fraudulent Microsoft accounts, which were used for various malicious purposes including phishing and account takeovers. The group was responsible for generating approximately 750 million illegal Outlook accounts, leading to significant financial gain through the sale of these credentials on dark web markets. In addition to their account-fraud activities, Storm-1152 provided CAPTCHA-solving services, which are often used by other malicious actors to bypass security measures in automated campaigns. The group's operations were extensive enough to connect them with ransomware and extortion groups, indicating a broader role in the cybercrime ecosystem. Microsoft took decisive action against Storm-1152 by obtaining a court order to seize their infrastructure, disrupting their operations and limiting their ability to continue illegal activities. This takedown highlights the importance of international cooperation and legal frameworks in combating cybercriminal organizations.
Key Capabilities
Campaigns & Victims
Storm-1152's campaigns likely focused on creating and distributing fraudulent Microsoft accounts, which could be used in various attacks. Their operations were large-scale, involving the creation of millions of illegal accounts, indicating a significant investment in infrastructure and resources. The group's provision of CAPTCHA-solving services suggests a support role for other cybercriminal activities, including potential phishing campaigns or botnet operations. While their exact operational tempo is unclear, the disruption of their infrastructure by Microsoft represents a significant blow to their ability to continue these activities. Notable past operations include the creation and sale of fraudulent accounts, which were used by other malicious actors, and their connection to ransomware groups.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium confidence in the available data, as Microsoft's takedown provides significant details but lacks specifics on some aspects like exact tools used or complete campaign timelines. Limited visibility into their exact operational methods and affiliations creates gaps in understanding their full threat profile.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics