Storm-3032 is a financially motivated extortion actor assessed to comprise members who splintered from the BlackFile group and now operate under the Helix banner. Its activity overlaps a threat pattern tracked by Google as UNC6671. Storm-3032 has been associated with social-engineering campaigns against corporate Microsoft 365 identities using impersonation of organizational IT help desks and passkey-, MFA-, or single-sign-on-themed lures. Operators use adversary-in-the-middle phishing and device-code phishing to obtain credentials, hijack authenticated sessions, or induce victims to authorize attacker-controlled clients. Following account compromise, they register attacker-controlled MFA methods for persistence, enumerate tenant users, groups, privileges, applications, authentication methods, and cloud resources through Microsoft Graph, and collect documents and email from SharePoint Online, OneDrive for Business, and Exchange Online. Collection is conducted in a throttled manner intended to reduce detection by volume-based controls.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A BlackFile splinter group operating under the Helix banner, associated with passkey, MFA, and SSO-themed phishing and account-compromise activity.
Conducts passkey-, MFA-, and SSO-themed social engineering against corporate accounts, followed by cloud-environment reconnaissance, MFA persistence, and systematic collection of Microsoft 365 data.
Associated with the initial-access techniques in an identity-focused Microsoft 365 intrusion campaign, including IT-helpdesk impersonation and passkey-themed phishing or device-code authentication flows intended to hijack user sessions.
Conducting a passkey-themed social-engineering and phishing campaign that steals credentials, takes over accounts, and gains access to and exfiltrates data from cloud resources.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.