HOMETHREATSStorm-1167
APT / THREAT GROUP

Storm-1167

🇮🇩Indonesia-attributed
1
campaigns
2
aliases
Last seen:Mar 17, 2026

Intelligence Profile

Storm-1167 is a threat actor tracked by Microsoft, known for their use of an AiTM phishing kit. They were responsible for launching an attack that led to Business Email Compromise activity.

Threat Analysis

Storm-1167 is a known-sophistication threat actor attributed to Indonesia, engaged in cyber operations with a primary motivation of unknown activity patterns.

Known Campaigns

Storm-1167 — Active Operations March 2026

Storm-1167 is a unknown-motivation threat actor attributed to ID. Storm-1167 is a threat actor tracked by Microsoft, known for their use of an AiTM phishing kit. They were responsible for launching an attack that led to Business Email Compromise activity....

ACTIVEMEDIUM2026

External References

Quick Facts

TypeAPT / Threat Group
Origin🇮🇩 Indonesia
Aliases2
SourceMalpedia

Also Known As

Storm-1167DEV-1167

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.
Storm-1167 — APT / Threat Group | Threat Intelligence | CTIWATCH.COM