Storm-2992

MISP
Tipo:
Unknown
Paese:
Unknown
Prima attivita:
Unknown
Dettagli:

Financially motivated threat actor tracked by Microsoft Threat Intelligence as the developer and support operator of the EvilTokens phishing-as-a-service platform, advertised and sold to other cybercriminals through Telegram channels. Storm-XXXX is Microsoft's designation for a developing or emerging activity cluster: the name is provisional and may be merged or renamed once attribution matures. Its infrastructure was disrupted by Microsoft's Digital Crimes Unit with partners in September 2026.

Metadata
ID: 1130
Created: 01/10/2026 16:00
Updated: 01/10/2026 16:00