Storm-1167 is an Indonesia-associated threat activity cluster conducting adversary-in-the-middle phishing against organizational Microsoft 365 accounts. Its activity is associated with FlowerStorm phishing infrastructure. Targets include businesses, universities, and international institutions, including organizations linked to the European Union and United Nations. The actor steals credentials and authenticated session cookies or tokens, allowing access to email and cloud resources despite multifactor authentication. Storm-1167 exploits trusted relationships by sending phishing messages from compromised employee and third-party business accounts. Its lures impersonate Microsoft authentication workflows and use procurement requests, bid invitations, and shared-document themes. Associated phishing flows employ fake document portals, CAPTCHA stages, cloned sign-in pages, and conditional redirection to conceal malicious pages from non-targeted visitors. Compromised mailboxes are subsequently used to distribute additional phishing messages internally and to external partners, extending the compromise chain. In an October 2023 intrusion, the actor sent more than 1,000 phishing emails from a compromised third-party account, then approximately 1,300 additional credential-harvesting emails from an internal account. It also created mailbox rules that moved messages containing selected keywords into a designated folder to delay detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with phishing infrastructure used in AiTM phishing operations.
AiTM phishing activity targeting universities, enterprises, multinational institutions, and EU/UN agencies using compromised organizational accounts, fake document portals, CAPTCHA stages, and cloned Microsoft login pages to steal credentials and session tokens.
Indonesia-linked threat actor cluster listed in Microsoft's naming taxonomy mapping.
Conducted an October 2023 business email compromise campaign using a compromised third-party account to send more than 1,000 phishing emails. Stolen session tokens enabled access to the customer's email and cloud services. A compromised internal account then sent another 1,300 credential-harvesting emails.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.