Storm-1575

Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:13:25

Targeted industries: professional-services technology-and-telecommunications

Context

Storm-1575 is a threat actor identified by Microsoft as being involved in phishing campaigns using the Dadsec platform. They utilize hundreds of Domain Generated Algorithm domains to host credential harvesting pages and target global organizations to steal Microsoft 365 credentials.

Reports & references

  • bridewell.com — Analysing Widespread Microsoft365 Credential Harvesting Campaign (report)
  • twitter.com — 1712936244987019704 (report)
  • raw.githubusercontent.com — Microsoftmapping (report)

External references