Storm-3121 is a Microsoft-tracked threat cluster associated with initial-access operations that lead to ShinyHunters and Falcon extortion activity. Since at least May 2026, it has been linked to social-engineering campaigns targeting corporate Microsoft 365 identities. Operators impersonate organizational IT help desks through phone calls, SMS, and, in some cases, compromised Microsoft Teams accounts, using urgent passkey, multifactor authentication, or single-sign-on update narratives. The campaigns use adversary-in-the-middle phishing to capture credentials and authenticated sessions, and device-code phishing to induce victims to authorize attacker-controlled clients. Post-compromise activity associated with this intrusion ecosystem includes registration of attacker-controlled MFA methods for persistence, Microsoft Graph-based tenant reconnaissance, and collection of documents and email from SharePoint Online, OneDrive for Business, and Exchange Online. Storm-3121 operates alongside other clusters in the broader extortion ecosystem, including Storm-3032, but Storm-3032 is a distinct cluster linked to BlackFile splinter actors operating under the Helix banner.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducts initial-access operations that provide access to ShinyHunters and Falcon.
Conducts passkey-, MFA-, and SSO-themed social-engineering campaigns to compromise corporate Microsoft accounts, establish sessions through adversary-in-the-middle phishing or device-code phishing, enumerate Microsoft cloud resources, establish MFA persistence, and collect Microsoft 365 data.
Associated with identity-focused social-engineering campaigns against Microsoft 365 users. The observed activity impersonates IT helpdesks through calls or messages to personal phone numbers, uses passkey-themed adversary-in-the-middle phishing or device-code flows to hijack sessions, registers attacker-controlled MFA methods for persistence, conducts Microsoft Graph reconnaissance, and systematically collects SharePoint, OneDrive, and Exchange data.
Conducting a passkey-themed social-engineering and phishing campaign that steals credentials, takes over accounts, and gains access to and exfiltrates data from cloud resources.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.