Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1133

Description

In early 2023, Microsoft In early 2023, observed a wave of activity from a Gaza-based group that we track as Storm-1133 targeting Israeli private sector energy, defense, and telecommunications organizations.

AI Analysis

· 1 week ago

Executive Summary

Storm-1133 is an unidentified Gaza-based threat actor observed in early 2023 targeting Israeli private sector energy, defense, and telecommunications organizations. This group likely operates with moderate sophistication and exhibits signs of cyber espionage or adversarial activity.

Goals & Targeting

Storm-1133 likely seeks to achieve strategic objectives potentially related to intelligence gathering, disruption of critical infrastructure, or influence in the targeted sectors. Their focus on specific industries suggests a calculated approach aimed at maximizing impact. The targeting of energy, defense, and telecommunications indicates an intent to compromise systems that are vital to national security and economic stability. Victims include private sector organizations, which may serve as proxies for accessing sensitive government-related information.

Enhanced Description

In early 2023, Microsoft detected a series of cyber activities attributed to a Gaza-based threat actor named Storm-1133. The actor targeted private sector energy, defense, and telecommunications organizations in Israel. While specific details about the nature of these attacks are limited, such targeting suggests an interest in critical infrastructure or sensitive information. Given the geographic and sectoral focus, Storm-1133 may be linked to broader geopolitical dynamics or regional instability. This actor's operations highlight potential risks to national security through cyber means.

Key Capabilities

  • Email phishing
  • Network infiltration
  • Credential dumping
  • Lateral movement

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access

ATT&CK Techniques

T1059
T1059.003
T1566
T1566.004

Software / Tooling

Mimikatz
Custom malware

Campaigns & Victims

Storm-1133 has been active since early 2023, with campaign activity focused on Israeli private sector organizations. The actor's operational patterns suggest a focus on stealth and persistence, possibly deploying custom tools to maintain access. No specific campaigns beyond the initial targeting have been widely reported, but the group appears to be relatively new to the threat landscape and may continue to evolve its tactics.

IOC Patterns

  • Spear-phishing emails targeting energy, defense, and telecom sectors
  • Network probing attempts against Israeli organizations
  • Presence of known APT tools in targeted networks

Recommended Actions

  • Implement robust email filters for phishing detection
  • Monitor network traffic for signs of lateral movement
  • Conduct regular endpoint security audits
  • Enhance multi-factor authentication (MFA) across critical systems

Suggested Tags

APC
cyber_espionage
regional_conflict
critical_infrastructure

Confidence Assessment

Low confidence due to limited data on Storm-1133's TTPs, tools, and specific campaign details. The threat actor remains poorly understood beyond initial sightings in early 2023.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APC
cyber_espionage
regional_conflict
critical_infrastructure

Details

Type
Unknown
Country of Origin
P
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.