Storm-1575 is a financially motivated cybercrime threat actor associated with phishing-as-a-service operations focused on harvesting Microsoft 365 credentials and authentication material at scale. The group has been linked to the DadSec platform and its later rebrands or successor offerings, including Phoenix, Rockstar 2FA, and Salty 2FA. Activity attributed to Storm-1575 has targeted organizations across many sectors and countries, with a strong emphasis on Western victims. Storm-1575 is known for large-scale credential phishing campaigns that commonly begin with email lures themed around shared documents, invoices, payment confirmations, employee communications, recordings, or security-related prompts. The actor has used phishing infrastructure that redirects victims through legitimate services before presenting counterfeit Microsoft 365 login pages. These phishing kits have incorporated CAPTCHA gates, victim-specific branding, and pre-populated email fields to increase plausibility. Reported tooling supports adversary-in-the-middle handling of multifactor authentication, enabling theft of credentials and authentication tokens rather than simple password collection alone. The actor’s operations are closely tied to the phishing-as-a-service ecosystem. DadSec was marketed as an Office 365 phishing service and later evolved into Rockstar 2FA, which provided customers with unique phishing pages and campaign management through Telegram. Rockstar 2FA commonly used decoy pages for direct visits and impersonated Microsoft login workflows to capture credentials and MFA tokens. Salty 2FA has been described as a newer offering attributed to the same actor. Storm-1575 has also been observed leveraging third-party criminal infrastructure, including RedVDS virtual server infrastructure, alongside other financially motivated groups. Victimology indicates broad opportunistic targeting rather than a single vertical, though financial services, manufacturing, local government, energy, and service-sector organizations have been prominently affected. The actor’s tradecraft includes credential theft, session or token theft to bypass MFA, phishing-based initial access, large-scale exfiltration of authentication data, and operational measures intended to hinder detection such as infrastructure masking and rapid domain turnover.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Microsoft-tracked activity cluster observed leveraging RedVDS infrastructure to facilitate phishing-led account compromise and downstream financial fraud (BEC/payment diversion).
Microsoft-tracked threat actor observed leveraging RedVDS infrastructure in support of phishing/BEC and financial fraud activity.
Named Microsoft-tracked threat actor group that leveraged RedVDS virtual Windows servers to support cyber-enabled crime (e.g., phishing, credential theft/account takeover, business email compromise/payment diversion, and related fraud).
Previously associated with the DadSec phishing service, which the content describes as an earlier version related to Rockstar2FA phishing-as-a-service activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.