Threat Actor Unknown origin
Storm-1567
Also known as: Akira · PUNK SPIDER · GOLD SAHARA
Storm-1567 is the threat actor behind the Ransomware-as-a-Service Akira. They attacked Swedish organizations in March 2023. This ransomware utilizes the ChaCha encryption algorithm, PowerShell, and Windows Management Instrumentation (WMI). Microsoft's Defender for Endpoint successfully blocked a large-scale hacking campaign carried out by Storm-1567, highlighting the effectiveness of their security solution.
Indicators of Compromise 16
Domain authorized-logins[.]net Domain b6w9m2z5x8q1v3k[.]top Domain carrolc[.]com SHA-256 1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984 SHA-256 34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bc SHA-256 3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4be SHA-256 59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712 SHA-256 8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235 SHA-256 afd5f1ed45a9867daf3bc64152cef460a06b164c8183e490db39146d4749a82c SHA-256 db972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5 SHA-256 f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344e SHA-256 fb3630822b70bacb56aa4cec29b5a0e3e9acb3920809e70310a4003385a6d34a IP 142[.]93[.]242[.]144 IP 144[.]31[.]53[.]78 IP 198[.]13[.]159[.]44 IP 199[.]91[.]221[.]42