Also known as: SnappyClient, YoroTrooper
Storm-1575 is a threat actor identified by Microsoft as being involved in phishing campaigns using the Dadsec platform. They utilize hundreds of Domain Generated Algorithm domains to host credential harvesting pages and target global organizations to steal Microsoft 365 credentials.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm-1575 is a threat actor identified by Microsoft in phishing campaigns leveraging the Dadsec platform. They employ Domain Generation Algorithms (DGAs) to host credential harvesting pages, targeting global organizations to steal Microsoft 365 credentials. Their activities suggest a focus on large-scale credential theft, potentially for long-term access or espionage.
Goals & Targeting
Storm-1575's strategic objective appears to be the theft of sensitive credentials, likely to enable unauthorized access to target organizations' Microsoft 365 environments. Their targeting profile is global, with a focus on industries and sectors that hold valuable data or provide strategic advantages. This suggests they may aim for espionage, financial gain, or other objectives that require prolonged access to targeted systems.
Enhanced Description
Storm-1575 operates as a sophisticated threat actor involved in phishing campaigns. Utilizing the Dadsec platform and Domain Generation Algorithms (DGAs), they create dynamic domains to host malicious pages designed to harvest Microsoft 365 credentials. This approach allows them to bypass traditional domain blacklisting techniques, making their campaigns persistent and challenging to detect. The use of credential harvesting indicates a strategic focus on access rather than immediate financial gain, which is often characteristic of advanced persistent threat (APT) groups aiming for long-term espionage or operational objectives.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
Storm-1575's campaigns exhibit a high level of persistence and adaptability. They target large organizations globally, leveraging phishing emails to distribute malicious links. Their use of DGAs for hosting credential-harvesting pages indicates an attempt to circumvent traditional domain-based detection mechanisms. Notable operations include the sustained targeting of Microsoft 365 credentials across various industries, suggesting a focus on long-term access rather than immediate impact.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data surrounding Storm-1575 is moderate. The actor's operational methods, such as phishing campaigns using DGAs, are well-documented by Microsoft. However, details on specific tools used or exact campaign goals remain unclear. Further analysis of their TTPs and associated infrastructure could provide deeper insights.
No campaigns linked yet.
No observed data linked yet.
18
Techniques
40
Tools
0
Campaigns
4
IOCs
0
Observed Data
1
Tactics