Storm-1575
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:13:25
Targeted industries: professional-services technology-and-telecommunications
Context
Storm-1575 is a threat actor identified by Microsoft as being involved in phishing campaigns using the Dadsec platform. They utilize hundreds of Domain Generated Algorithm domains to host credential harvesting pages and target global organizations to steal Microsoft 365 credentials.
Reports & references
- bridewell.com — Analysing Widespread Microsoft365 Credential Harvesting Campaign (report)
- twitter.com — 1712936244987019704 (report)
- raw.githubusercontent.com — Microsoftmapping (report)