Storm-1295 is a threat actor group operating the Greatness phishing-as-a-service platform since mid-2022.
Analyst brief
Storm-1295 is a threat actor group active since mid-2022, tracked by Microsoft for operating the Greatness phishing-as-a-service (PhaaS) platform. They offer their services to other attackers, primarily targeting credentials through adversary-in-the-middle techniques. Key TTPs include using synchronous relay servers to serve replicas of sign-in pages, effectively bypassing standard phishing defenses. Defenders should focus on detecting and mitigating real-time credential interception, especially attempts to bypass multi-factor authentication (MFA).
Storm-1295
DEV-1295
unknown
Storm-1295 is a threat actor group that operates the Greatness phishing-as-a-service platform. They utilize synchronous relay servers to present targets with a replica of a sign-in page, resembling traditional phishing attacks. Their adversary-in-the-middle capability allows Storm-1295 to offer their services to other attackers. Active since mid-2022, Storm-1295 is tracked by Microsoft and is known for their involvement in the Greatness PhaaS platform.