Storm-1167
Storm-1167 is a threat actor tracked by Microsoft, known for their use of an AiTM phishing kit. They were responsible for launching an attack that led to Business Email Compromise activity.
Storm-1167 is a Microsoft-tracked threat actor known for AiTM phishing and Business Email Compromise activity.
Storm-1167 is a threat actor tracked by Microsoft, recognized for utilizing an AiTM (Adversary-in-The-Middle) phishing kit. The group primarily targets organizations to conduct Business Email Compromise (BEC) activity, often bypassing multi-factor authentication to hijack session tokens. Their key TTP involves AiTM phishing to steal credentials and session cookies, enabling subsequent invoice fraud or email forwarding for BEC. Defenders must focus on training users against AiTM phishing attempts, monitoring for anomalous session token usage, and implementing quick session revocation policies for suspicious logins.
Storm-1167 is a threat actor tracked by Microsoft, known for their use of an AiTM phishing kit. They were responsible for launching an attack that led to Business Email Compromise activity.
The Storm-1167 threat actor primarily targets organizations to conduct Business Email Compromise (BEC) activity.
Storm-1167 bypasses multi-factor authentication by using AiTM (Adversary-in-The-Middle) phishing to hijack session tokens.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.