| SYMBOL | COMMON_NAME | aka. SYNONYMS |
Financially motivated threat actor tracked by Microsoft Threat Intelligence as the developer and support operator of the EvilTokens phishing-as-a-service platform, advertised and sold to other cybercriminals through Telegram channels. Storm-XXXX is Microsoft's designation for a developing or emerging activity cluster: the name is provisional and may be merged or renamed once attribution matures. Its infrastructure was disrupted by Microsoft's Digital Crimes Unit with partners in September 2026.
There are currently no families associated with this actor.
| 2026-09-22
⋅
Microsoft
⋅
Unmasking EvilTokens: Getting to the root of device code phishing Storm-2992 |