Storm-1152

Origin
VN
Primary motivation
financial-gain
Sophistication
expert
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:13:12

Targeted industries: technology-and-telecommunications financial-services

Context

Storm-1152, a cybercriminal group, was recently taken down by Microsoft for illegally reselling Outlook accounts. They operated by creating approximately 750 million fraudulent Microsoft accounts and earned millions of dollars in illicit revenue. Storm-1152 also offered CAPTCHA-solving services and was connected to ransomware and extortion groups. Microsoft obtained a court order to seize their infrastructure and domains, disrupting their operations.

Reports & references

  • rewterz.com — Rewterz Threat Update Microsoft Warns Of Emerging Threat By Storm 0539 Behind Gift Card Frauds (report)
  • securityboulevard.com — Microsoft Storm 1152 Crackdown Stopping Threat Actors (report)
  • Microsoft — Cybercrime Cybersecurity Storm 1152 Fraudulent Accounts (report)
  • raw.githubusercontent.com — Microsoftmapping (report)

External references