Storm-0940 (301ffea9-edd5-4d89-a65f-8add8e34e95d)
Storm-0940 is a Chinese threat actor active since at least 2021, known for gaining initial access through password spray and brute-force attacks, as well as exploiting network edge applications. Microsoft has observed Storm-0940 utilizing valid credentials obtained from CovertNetwork-1658's password spray operations, indicating a close operational relationship between the two. Once inside a victim environment, Storm-0940 has been seen leveraging compromised credentials for further malicious activities. Additionally, Storm-0940 has employed botnets, such as Quad7, to facilitate password spraying attacks.
| Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
|---|---|---|---|---|
| Storm-0940 (c83eb0f5-eaff-5b3b-b938-4f9068255bf7) | Microsoft Activity Group actor | Storm-0940 (301ffea9-edd5-4d89-a65f-8add8e34e95d) | Threat Actor | 1 |