Storm-1167
Aliases: DEV-1167
- First seen
- 2023-07-15 00:00:00
- Origin
- ID
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:13:01
Targeted industries: financial-services professional-services
Targeted regions: country_code:us country_code:gb country_code:au
Context
Storm-1167 is a threat actor tracked by Microsoft, known for their use of an AiTM phishing kit. They were responsible for launching an attack that led to Business Email Compromise activity.
Reports & references
- Microsoft — Detecting And Mitigating A Multi Stage Aitm Phishing And Bec Campaign (report)