SYMBOLCOMMON_NAMEaka. SYNONYMS

Storm-2992  (Back to overview)


Financially motivated threat actor tracked by Microsoft Threat Intelligence as the developer and support operator of the EvilTokens phishing-as-a-service platform, advertised and sold to other cybercriminals through Telegram channels. Storm-XXXX is Microsoft's designation for a developing or emerging activity cluster: the name is provisional and may be merged or renamed once attribution matures. Its infrastructure was disrupted by Microsoft's Digital Crimes Unit with partners in September 2026.


Associated Families

There are currently no families associated with this actor.


References
2026-09-22 ⋅ Microsoft ⋅ Microsoft Defender Experts, Microsoft Security Research, Microsoft Threat Intelligence
Unmasking EvilTokens: Getting to the root of device code phishing
Storm-2992

Credits: MISP Project