Storm-3032 is a financially motivated extortion actor cluster composed of operators that splintered from the BlackFile group and operate under the Helix extortion banner. It has been linked to cloud-identity initial-access operations targeting Microsoft 365 environments. These operations use helpdesk-impersonation social engineering, including telephone, SMS, and compromised collaboration-account lures themed around passkey, MFA, or SSO updates. Victims are induced to complete adversary-in-the-middle phishing or device-code authorization flows, enabling theft or abuse of credentials and session tokens. Following access, the operators can register attacker-controlled MFA methods for persistence, enumerate tenant identities, roles, applications, authentication methods, cloud storage, and mail through Microsoft Graph, and systematically collect documents and email from SharePoint Online, OneDrive for Business, and Exchange Online. The observed activity includes Valid Accounts: Cloud Accounts, Modify Authentication Process: Multi-Factor Authentication, Data from Cloud Storage, Email Collection, and Exfiltration Over Web Service.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.