Storm-1567 operates the Akira Ransomware-as-a-Service targeting professional services, manufacturing, and finance sectors.
Analyst brief
Storm-1567, also known as Akira, is a threat group operating the Akira Ransomware-as-a-Service and has targeted sectors like professional services, manufacturing, and finance primarily in the US, Canada, and Europe. They leverage external remote services like RDP for initial access and use dual-use tools such as PowerShell, Mimikatz, PsExec, and Rclone for lateral movement, credential theft, and data exfiltration to cloud storage. Their key TTPs include disabling security tools, stealing Kerberos tickets, and deploying ransomware like Akira_v2 and Megazord. Defenders should focus on securing RDP endpoints, monitoring suspicious PowerShell and WMI activity, and tracking unusual cloud storage connections indicative of exfiltration.
Storm-1567
AkiraPUNK SPIDERGOLD SAHARA
activeunknown
Storm-1567 is the threat actor behind the Ransomware-as-a-Service Akira. They attacked Swedish organizations in March 2023. This ransomware utilizes the ChaCha encryption algorithm, PowerShell, and Windows Management Instrumentation (WMI). Microsoft's Defender for Endpoint successfully blocked a large-scale hacking campaign carried out by Storm-1567, highlighting the effectiveness of their security solution.
target countries (as stated by the source)
United StatesCanadaUnited KingdomSwitzerland
target sectors
Professional ServicesManufacturingRetail & E-CommerceTechnology