Storm-2992Storm-2992

Also known as: Storm-2992

Known aliases
1

Profile

Financially motivated threat actor tracked by Microsoft Threat Intelligence as the developer and support operator of the EvilTokens phishing-as-a-service platform, advertised and sold to other cybercriminals through Telegram channels. Storm-XXXX is Microsoft's designation for a developing or emerging activity cluster: the name is provisional and may be merged or renamed once attribution matures. Its infrastructure was disrupted by Microsoft's Digital Crimes Unit with partners in September 2026.

Aliases· 1

Storm-2992
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.