Storm-1567 (3a912680-6f38-4fe7-9941-744f0e2280b3)
Storm-1567 is the threat actor behind the Ransomware-as-a-Service Akira. They attacked Swedish organizations in March 2023. This ransomware utilizes the ChaCha encryption algorithm, PowerShell, and Windows Management Instrumentation (WMI). Microsoft's Defender for Endpoint successfully blocked a large-scale hacking campaign carried out by Storm-1567, highlighting the effectiveness of their security solution.
| Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
|---|---|---|---|---|
| Storm-1567 (ba96d568-f803-50c9-907b-d11947123257) | Microsoft Activity Group actor | Storm-1567 (3a912680-6f38-4fe7-9941-744f0e2280b3) | Threat Actor | 1 |