Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1575

Also known as: SnappyClient, YoroTrooper

Description

Storm-1575 is a threat actor identified by Microsoft as being involved in phishing campaigns using the Dadsec platform. They utilize hundreds of Domain Generated Algorithm domains to host credential harvesting pages and target global organizations to steal Microsoft 365 credentials.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Media
Aviation
Manufacturing
Retail
Healthcare
Telecommunications
Non profit
Transportation
Critical infrastructure
Education
Think tank

Targeted Countries / Regions

RU
US
SG
AU
VN
IN
IL
FR
IT
RO
EG
BR
NL
KP

AI Analysis

· 1 week ago

Executive Summary

Storm-1575 is a threat actor identified by Microsoft in phishing campaigns leveraging the Dadsec platform. They employ Domain Generation Algorithms (DGAs) to host credential harvesting pages, targeting global organizations to steal Microsoft 365 credentials. Their activities suggest a focus on large-scale credential theft, potentially for long-term access or espionage.

Goals & Targeting

Storm-1575's strategic objective appears to be the theft of sensitive credentials, likely to enable unauthorized access to target organizations' Microsoft 365 environments. Their targeting profile is global, with a focus on industries and sectors that hold valuable data or provide strategic advantages. This suggests they may aim for espionage, financial gain, or other objectives that require prolonged access to targeted systems.

Enhanced Description

Storm-1575 operates as a sophisticated threat actor involved in phishing campaigns. Utilizing the Dadsec platform and Domain Generation Algorithms (DGAs), they create dynamic domains to host malicious pages designed to harvest Microsoft 365 credentials. This approach allows them to bypass traditional domain blacklisting techniques, making their campaigns persistent and challenging to detect. The use of credential harvesting indicates a strategic focus on access rather than immediate financial gain, which is often characteristic of advanced persistent threat (APT) groups aiming for long-term espionage or operational objectives.

Key Capabilities

  • Phishing campaign orchestration
  • Domain Generation Algorithm (DGA) usage for creating malicious domains
  • Credential harvesting via phishing pages
  • Persistence in campaigns despite updates or defenses

MITRE ATT&CK Tactics

Phishing

Software / Tooling

Dadsec platform
Custom credential-harvesting tools
Domain Generation Algorithm (DGA) tools

Campaigns & Victims

Storm-1575's campaigns exhibit a high level of persistence and adaptability. They target large organizations globally, leveraging phishing emails to distribute malicious links. Their use of DGAs for hosting credential-harvesting pages indicates an attempt to circumvent traditional domain-based detection mechanisms. Notable operations include the sustained targeting of Microsoft 365 credentials across various industries, suggesting a focus on long-term access rather than immediate impact.

IOC Patterns

  • Spear-phishing emails with malicious links
  • Domain Generation Algorithm (DGA)-based domains
  • Hosting credential-harvesting pages on compromised websites

Recommended Actions

  • Implement multi-factor authentication (MFA) for Microsoft 365 accounts
  • Educate users about phishing indicators and suspicious emails
  • Monitor for DGA-based domain registration activity in the network
  • Use endpoint detection and response (EDR) solutions to detect malicious activity
  • Regularly update and patch Microsoft 365 environments

Suggested Tags

APT
Phishing
Espionage
Credential Theft

Confidence Assessment

Confidence in the data surrounding Storm-1575 is moderate. The actor's operational methods, such as phishing campaigns using DGAs, are well-documented by Microsoft. However, details on specific tools used or exact campaign goals remain unclear. Further analysis of their TTPs and associated infrastructure could provide deeper insights.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.group-ib.com — Cited by web research for: SnappyClient
  2. attack.mitre.org — Cited by web research for: T1437
  3. learn.microsoft.com — Cited by web research for: Chollima

Intel Summary

18

Techniques

40

Tools

0

Campaigns

4

IOCs

0

Observed Data

1

Tactics

Tags

Phishing
APT
Espionage
Credential Theft

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.