Storm-0867, active since 2012, is known for intercepting communications to steal sessions and bypass multifactor authentication.
Analyst brief
Storm-0867 (DEV-0867) is a threat actor active since 2012, known for intercepting and manipulating communications between victims and legitimate services. They target various industries and regions, focusing on password theft, session hijacking, bypassing multifactor authentication, and modifying authentication methods. Their key TTPs include sophisticated phishing campaigns using the Caffeine phishing-as-a-service platform and social engineering. Defenders should prioritize monitoring for session token capture and suspicious changes to authentication methods, as well as training users against advanced phishing tactics.
Storm-0867
DEV-0867
unknown
Storm-0867 is a threat actor that has been active since 2012 and has targeted various industries and regions. They employ sophisticated phishing campaigns, utilizing social engineering techniques and a phishing as a service platform called Caffeine. Their attacks involve intercepting and manipulating communication between users and legitimate services, allowing them to steal passwords, hijack sign-in sessions, bypass multifactor authentication, and modify authentication methods.