Skip to content
skopnix
← adversaries
Unknown · assessed origin Vietnam

Storm-1152

misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

Storm-1152, a cybercriminal group, was recently taken down by Microsoft for illegally reselling Outlook accounts. They operated by creating approximately 750 million fraudulent Microsoft accounts and earned millions of dollars in illicit revenue. Storm-1152 also offered CAPTCHA-solving services and was connected to ransomware and extortion groups. Microsoft obtained a court order to seize their infrastructure and domains, disrupting their operations.

Take it with you
References
Early access

Track Storm-1152 on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected