Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0835

Description

Cybercriminals have launched a phishing campaign targeting senior executives in U.S. firms, using the EvilProxy phishing toolkit for credential harvesting and account takeover attacks. This campaign, initiated in July 2023, primarily targets sectors such as banking, financial services, insurance, property management, real estate, and manufacturing. The attackers exploit an open redirection vulnerability on the job search platform "indeed.com," redirecting victims to malicious phishing pages impersonating Microsoft. EvilProxy functions as a reverse proxy, intercepting credentials, two-factor authentication codes, and session cookies to hijack accounts. The threat actors, known as Storm-0835 by Microsoft, have hundreds of customers who pay monthly fees for their services, making attribution difficult. The attacks involve sending phishing emails with deceptive links to Indeed, redirecting victims to EvilProxy pages for credential harvesting.

AI Analysis

· 1 week ago

Executive Summary

Storm-0835, a cybercriminal group identified by Microsoft, operates using the EvilProxy phishing toolkit to target senior executives in U.S. firms across banking, financial services, and manufacturing sectors. Their campaign exploits vulnerabilities on job platforms like Indeed.com for credential harvesting and account takeovers, leveraging reverse proxy techniques to intercept login details and session cookies.

Goals & Targeting

Storm-0835's primary goal appears to be financial gain through credential harvesting and account takeovers. They specifically target senior executives due to their access to sensitive corporate data and high-value accounts in sectors with significant financial stakes. The group's focus on U.S.-based firms suggests a strategic approach to capitalize on the lucrative nature of these industries.

Enhanced Description

Storm-0835 is a cybercriminal group uncovered by Microsoft, utilizing the EvilProxy phishing toolkit in their attacks. They target high-ranking executives primarily in the United States across sectors such as banking, financial services, insurance, property management, real estate, and manufacturing. Their modus operandi involves sending phishing emails that direct victims to malicious pages via an open redirection vulnerability on Indeed.com. These pages mimic Microsoft's login interface, allowing the attackers to intercept credentials, two-factor authentication codes, and session cookies through EvilProxy, a reverse proxy tool designed for credential harvesting and account hijacking. The group is known to offer their services under a cybercriminal-as-a-service model, recruiting hundreds of customers who pay monthly fees. This business model complicates direct attribution as multiple actors may utilize the same tools。

Key Capabilities

  • Phishing campaign orchestration
  • Exploitation of open redirection vulnerabilities
  • Use of EvilProxy for credential interception
  • Reverse proxy techniques
  • High-level social engineering

MITRE ATT&CK Tactics

Credential Access
Execution
Phishing

ATT&CK Techniques

T1059.003 - Spear Phishing with Attachment
T1566.001 - Credential Harvesting via Reverse Proxy
T1194 - Exploitation for Credential Access

Software / Tooling

EvilProxy
Custom Phishing Tools

Campaigns & Victims

Storm-0835 has been observed in an active campaign since July 2023, primarily targeting executives in the U.S. Their campaigns show a high level of organization, using phishing emails and malicious redirects to compromise credentials. The group's services being sold under a cybercriminal-as-a-service model indicates potential widespread adoption of their tools across multiple actors, making long-term tracking difficult. Notable past operations include credential harvesting from financial institutions and real estate companies via EvilProxy.

IOC Patterns

  • Spear-phishing emails with links to Indeed.com
  • Malicious domains mimicking Microsoft login pages
  • Reverse proxy traffic patterns intercepting session data

Recommended Actions

  • Implement multi-factor authentication (MFA)
  • Conduct regular phishing awareness training for executives
  • Monitor network traffic for suspicious activity from known phishing domains
  • Secure third-party vendor services like Indeed.com
  • Enhance employee training on identifying phishing attempts
  • Perform regular risk assessments of sensitive corporate accounts

Suggested Tags

Cybercrime
Phishing
Financial Fraud
Corporate Espionage

Confidence Assessment

Confidence in the analysis is medium to high. The data is sufficient for understanding their operational methods and tools, but gaps exist regarding their exact location, full scope of operations beyond 2023, and long-term strategic goals. Additional information on campaign history, specific TTPs, and associated infrastructure would enhance confidence.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Phishing
Cybercrime
Financial Fraud
Corporate Espionage

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.