Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1152

Description

Storm-1152, a cybercriminal group, was recently taken down by Microsoft for illegally reselling Outlook accounts. They operated by creating approximately 750 million fraudulent Microsoft accounts and earned millions of dollars in illicit revenue. Storm-1152 also offered CAPTCHA-solving services and was connected to ransomware and extortion groups. Microsoft obtained a court order to seize their infrastructure and domains, disrupting their operations.

AI Analysis

· 1 week ago

Executive Summary

Storm-1152 is a cybercriminal group primarily engaged in fraudulent activities, including the creation of millions of illegal Microsoft accounts and offering CAPTCHA-solving services. Associated with ransomware and extortion operations, they were successfully disrupted by Microsoft through legal action, though their full capabilities and threat trajectory remain partially understood.

Goals & Targeting

Storm-1152's primary goals appear to be financial gain through the sale of fraudulent accounts and the provision of services that enable other cybercriminal activities. Their targeting focuses on creating and monetizing large volumes of illegal Microsoft accounts, which can be used for various malicious purposes such as phishing,诈骗, and unauthorized access. The group likely targets sectors with high reliance on digital communication and online services, potentially including industries like technology, healthcare, and education, where the possession of legitimate-seeming accounts could provide significant value. Their association with ransomware groups suggests an interest in supporting broader extortion campaigns.

Enhanced Description

Storm-1152 operates as a cybercriminal group specializing in the creation of fraudulent Microsoft accounts, which were used for various malicious purposes including phishing and account takeovers. The group was responsible for generating approximately 750 million illegal Outlook accounts, leading to significant financial gain through the sale of these credentials on dark web markets. In addition to their account-fraud activities, Storm-1152 provided CAPTCHA-solving services, which are often used by other malicious actors to bypass security measures in automated campaigns. The group's operations were extensive enough to connect them with ransomware and extortion groups, indicating a broader role in the cybercrime ecosystem. Microsoft took decisive action against Storm-1152 by obtaining a court order to seize their infrastructure, disrupting their operations and limiting their ability to continue illegal activities. This takedown highlights the importance of international cooperation and legal frameworks in combating cybercriminal organizations.

Key Capabilities

  • Fraudulent account creation
  • CAPTCHA-solving services
  • Large-scale infrastructure operation
  • Affiliation with ransomware/extortion networks

Campaigns & Victims

Storm-1152's campaigns likely focused on creating and distributing fraudulent Microsoft accounts, which could be used in various attacks. Their operations were large-scale, involving the creation of millions of illegal accounts, indicating a significant investment in infrastructure and resources. The group's provision of CAPTCHA-solving services suggests a support role for other cybercriminal activities, including potential phishing campaigns or botnet operations. While their exact operational tempo is unclear, the disruption of their infrastructure by Microsoft represents a significant blow to their ability to continue these activities. Notable past operations include the creation and sale of fraudulent accounts, which were used by other malicious actors, and their connection to ransomware groups.

IOC Patterns

  • Massive volume of newly created or unauthorized accounts
  • Use of CAPTCHA-solving services in support of campaigns
  • Distribution of Microsoft account credentials through dark web markets

Recommended Actions

  • Enhance account security measures for Microsoft products
  • Monitor for unusual activity related to bulk account creation
  • Implement additional authentication layers for sensitive accounts
  • Educate employees about phishing and account compromise risks
  • Conduct regular audits of user accounts for unauthorized access

Suggested Tags

cybercrime
fraud
ransomware
account-theft

Confidence Assessment

Medium confidence in the available data, as Microsoft's takedown provides significant details but lacks specifics on some aspects like exact tools used or complete campaign timelines. Limited visibility into their exact operational methods and affiliations creates gaps in understanding their full threat profile.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
cybercrime
fraud
ransomware
account-theft

Details

Type
Unknown
Country of Origin
V
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.