Storm-1575 uses the Dadsec platform to deploy DGA domains for Microsoft 365 credential phishing.
Analyst brief
Storm-1575 is a threat actor identified by Microsoft, known for conducting phishing campaigns using the Dadsec platform. They primarily target global organizations. Their main TTP involves deploying hundreds of DGA domains to host credential harvesting pages for stealing Microsoft 365 credentials. Defenders should focus on monitoring for anomalous DGA domains, enforcing multi-factor authentication, and raising user awareness against targeted phishing attacks.
Storm-1575
unknown
Storm-1575 is a threat actor identified by Microsoft as being involved in phishing campaigns using the Dadsec platform. They utilize hundreds of Domain Generated Algorithm domains to host credential harvesting pages and target global organizations to steal Microsoft 365 credentials.