Storm-1152 is a financially motivated cybercriminal group assessed to operate from Vietnam. The group is known for large-scale creation and sale of fraudulent email accounts, including Microsoft accounts, which were supplied to other criminal actors and nation-state operators. Its activity supported downstream abuse by enabling access, anonymity, and account-based fraud for a broader threat ecosystem. Storm-1152 used highly automated account-generation workflows and incorporated CAPTCHA-bypass capabilities, including AI-enabled automation, to create fraudulent accounts at industrial scale. Public reporting has described the group producing tens of millions of fake accounts per month at peak volume and hundreds of millions overall before disruption actions significantly degraded its operations. The actor’s core role in the intrusion lifecycle is as an enabler and supplier rather than a conventional intrusion operator. Its demonstrated capabilities center on initial access support, spoofing through fraudulent identity and account creation, and financially motivated criminal services. Storm-1152 has been linked to sales of fraudulent accounts to both cybercriminal groups and nation-state customers, including actors associated with social-engineering-heavy intrusion activity. No high-confidence evidence in the supplied facts supports ransomware operations, destructive activity, or direct victim targeting by industry or country beyond its role as a criminal service provider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated threat actor cluster tracked by Microsoft.
Vietnam-based cybercrime service provider described as mass-creating fraudulent email accounts at scale and selling them to other threat actors; used automation (including AI) to bypass CAPTCHA and enable account creation/fraud supply chain services.
Mentioned as a specific threat actor in the context of Microsoft’s incident response (DART) and threat intelligence (MSTIC) collaboration; no further operational details provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.