Storm-1101 is a Microsoft-tracked cybercriminal threat actor associated with the phishing and initial-access portion of the ransomware ecosystem. The actor is characterized as specializing in the creation of phishing landing pages and related lures rather than conducting full end-to-end intrusions itself, aligning it with an initial access broker role. Its activity centers on building deceptive web infrastructure used to capture victims or facilitate follow-on compromise by other criminal operators. High-confidence reporting directly ties Storm-1101 to phishing-kit landing page creation, making initial access its defining capability and suggesting a financially motivated role within broader cybercrime operations, including ransomware enablement.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Specialized phishing infrastructure operator that creates phishing landing pages; supports the broader ransomware ecosystem by enabling credential theft and downstream initial access brokering.
Specialized phishing infrastructure operator focused on creating phish-kit landing pages used for credential theft; supports broader cybercrime/ransomware ecosystems by enabling credential harvesting and downstream initial access sales.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.