Storm-1167 is a Microsoft-tracked emerging threat cluster associated with adversary-in-the-middle phishing operations focused on stealing authenticated Microsoft 365 sessions. The activity has been linked to procurement- and project-themed phishing campaigns that abuse compromised organizational Outlook accounts to resend lures internally and to trusted external partners, increasing credibility and enabling rapid propagation across victim ecosystems. Observed targets include universities, enterprises, multinational institutions, and organizations associated with the European Union and United Nations. The actor’s tradecraft centers on real-time reverse-proxy phishing using multiple AiTM kits, including FlowerStorm, EvilProxy, Evilginx, and Kali365. Victims are commonly directed through fake document portals, CAPTCHA stages, and cloned Microsoft 365 authentication pages that impersonate trusted brands and institutions. These phishing workflows relay credentials and MFA interactions to legitimate services while intercepting session cookies and authentication tokens, allowing Storm-1167 to hijack authenticated sessions and access Outlook, SharePoint, and other Microsoft 365 resources without defeating MFA cryptographically. Storm-1167 has demonstrated operational use of compromised aged domains and likely compromised websites rather than relying solely on newly registered phishing infrastructure. Reported infrastructure patterns include RDGA-style domain naming, phishing-oriented subdomain conventions, conditional cloaking for non-targeted visitors, and injected web content used to host fake download or login pages. After obtaining access, the actor has been associated with mailbox abuse, SaaS account takeover, internal reconnaissance through email and document access, and reuse of newly compromised accounts to expand phishing operations. Storm-1167 is a temporary Microsoft designation for an emerging or not-yet-fully-attributed cluster rather than a confirmed nation-state or formally attributed criminal group. Based on observed behavior, the actor is best characterized as a phishing and session-hijacking operator primarily targeting business and institutional workflows for account compromise and downstream fraud or unauthorized access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with phishing infrastructure used in AiTM phishing operations.
AiTM phishing activity targeting universities, enterprises, multinational institutions, and EU/UN agencies using compromised organizational accounts, fake document portals, CAPTCHA stages, and cloned Microsoft login pages to steal credentials and session tokens.
Indonesia-linked threat actor cluster listed in Microsoft's naming taxonomy mapping.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.