Storm-1167 is a Microsoft-tracked emerging threat cluster associated with adversary-in-the-middle phishing operations designed to steal credentials, session cookies, and MFA-authenticated tokens in real time. The actor has targeted universities, enterprises, multinational institutions, and organizations associated with the European Union and United Nations, with lures centered on procurement, project collaboration, requests for information, bid invitations, and shared document workflows. The cluster is characterized by the use of multiple AiTM phishing kits, including Evilginx, EvilProxy, FlowerStorm, and Kali365. Its phishing chains commonly begin with emails sent from compromised organizational accounts to increase credibility and facilitate internal and external propagation. Victims are typically directed to fake document portals, CAPTCHA or anti-bot stages, and then cloned authentication pages impersonating trusted brands and services such as Microsoft and other business or institutional portals. These phishing workflows are intended to proxy authentication sessions live, allowing the actor to capture authenticated session material rather than merely collecting usernames and passwords, thereby defeating MFA protections through session hijacking rather than direct MFA bypass. Storm-1167 has also been observed personalizing phishing flows, cloaking content from non-targeted visitors, and reusing infrastructure patterns across campaigns. Reported infrastructure tradecraft includes the use of aged or likely compromised domains instead of exclusively newly registered phishing sites, as well as domain and subdomain naming conventions consistent with kit reuse and operational standardization. FlowerStorm has been associated with this activity as both an alias and a kit designation tied to the cluster. Storm-1167 remains a developing or unclassified designation under Microsoft’s weather-themed taxonomy. Based on currently available information, it is best described as a phishing-focused intrusion cluster rather than a formally attributed nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AiTM phishing activity targeting universities, enterprises, multinational institutions, and EU/UN agencies using compromised organizational accounts, fake document portals, CAPTCHA stages, and cloned Microsoft login pages to steal credentials and session tokens.
Indonesia-linked threat actor cluster listed in Microsoft's naming taxonomy mapping.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.