Storm-1295

Aliases: DEV-1295

First seen
2022-06-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:12:59

Targeted industries: technology-and-telecommunications financial-services retail-and-hospitality

Context

Storm-1295 is a threat actor group that operates the Greatness phishing-as-a-service platform. They utilize synchronous relay servers to present targets with a replica of a sign-in page, resembling traditional phishing attacks. Their adversary-in-the-middle capability allows Storm-1295 to offer their services to other attackers. Active since mid-2022, Storm-1295 is tracked by Microsoft and is known for their involvement in the Greatness PhaaS platform.

Reports & references

  • Microsoft — 3860740 (report)
  • twitter.com — 1696273952870367320 (report)

External references