Storm-1977 is a threat actor tracked by Microsoft that has conducted password-spraying operations against cloud tenants in the education sector. The actor has been observed using the AzureChecker tool to validate credentials against targeted tenants by combining target account data with username-and-password combinations, indicating a focus on cloud identity compromise as an initial access vector. In at least one confirmed intrusion, Storm-1977 successfully compromised a cloud account through a guest user account, then created a resource group and deployed more than 200 containers for cryptomining. This activity demonstrates a progression from credential-based initial access to post-compromise abuse of cloud and container resources for illicit monetization. The operation reflects resource hijacking in cloud environments rather than ransomware or destructive activity. Observed tradecraft supports assessment of capabilities including brute-force password attacks, initial access through compromised credentials, post-exploitation within cloud environments, and crypto-theft through unauthorized cryptomining. Storm-1977 has specifically been associated with attacks on education-sector cloud tenants. No high-confidence attribution to a nation-state or specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Password-spraying against education-sector cloud tenants using AzureChecker, leading to deployment of large numbers of cryptomining containers.
Conducts password-spraying against Microsoft cloud (Azure) tenants in the education sector using AzureChecker.exe to validate credentials, then abuses compromised access to create Azure resource groups and large numbers of containers for cryptomining.
Conducting password-spraying attacks against cloud tenants (notably in education) to gain access and then hijack cloud/container resources (Kubernetes/containerized assets) for cryptomining.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.