Berliner Boersenzeitung - What is Storm-1152, alleged top creator of fake Microsoft accounts?

EUR -
AED 4.102105
AFN 75.943776
ALL 98.559302
AMD 432.564919
ANG 2.012493
AOA 1053.718626
ARS 1078.246379
AUD 1.615995
AWG 2.013058
AZN 1.903018
BAM 1.956263
BBD 2.254705
BDT 133.431563
BGN 1.95567
BHD 0.420474
BIF 3227.592984
BMD 1.116814
BND 1.432422
BOB 7.716309
BRL 6.068661
BSD 1.116649
BTN 93.443216
BWP 14.597564
BYN 3.654164
BYR 21889.557957
BZD 2.250874
CAD 1.510324
CDF 3199.673034
CHF 0.93949
CLF 0.036393
CLP 1004.183913
CNY 7.830771
CNH 7.796932
COP 4662.174305
CRC 579.581211
CUC 1.116814
CUP 29.595576
CVE 110.844247
CZK 25.143401
DJF 198.480656
DKK 7.45943
DOP 67.511856
DZD 147.632829
EGP 53.951777
ERN 16.752213
ETB 133.128577
FJD 2.438568
FKP 0.85052
GBP 0.835251
GEL 3.038171
GGP 0.85052
GHS 17.612595
GIP 0.85052
GMD 76.506072
GNF 9640.902719
GTQ 8.637546
GYD 233.589897
HKD 8.679836
HNL 27.775602
HRK 7.593232
HTG 147.162717
HUF 397.072547
IDR 16891.646973
ILS 4.169519
IMP 0.85052
INR 93.498064
IQD 1463.026578
IRR 47023.461504
ISK 150.960204
JEP 0.85052
JMD 175.431498
JOD 0.791491
JPY 158.829409
KES 144.069421
KGS 94.039997
KHR 4539.850039
KMF 493.213107
KPW 1005.13213
KRW 1463.356082
KWD 0.34064
KYD 0.930595
KZT 535.615475
LAK 24662.053383
LBP 100066.551049
LKR 333.41887
LRD 216.410712
LSL 19.192495
LTL 3.297662
LVL 0.67555
LYD 5.294124
MAD 10.82556
MDL 19.447167
MGA 5082.621727
MKD 61.575479
MMK 3627.368897
MNT 3794.934539
MOP 8.941976
MRU 44.354319
MUR 51.318034
MVR 17.154688
MWK 1938.789804
MXN 21.993751
MYR 4.606902
MZN 71.336549
NAD 19.192495
NGN 1863.393714
NIO 41.102919
NOK 11.725475
NPR 149.506067
NZD 1.76137
OMR 0.429471
PAB 1.116634
PEN 4.187052
PGK 4.437666
PHP 62.551688
PKR 310.143432
PLN 4.278011
PYG 8716.061777
QAR 4.066042
RON 4.979097
RSD 117.161668
RUB 105.231058
RWF 1487.59649
SAR 4.189354
SBD 9.261119
SCR 14.79953
SDG 671.767835
SEK 11.271168
SGD 1.429415
SHP 0.85052
SLE 25.516192
SLL 23419.029236
SOS 637.701275
SRD 34.286758
STD 23115.798718
SVC 9.770311
SYP 2806.029064
SZL 19.192494
THB 36.151687
TJS 11.881355
TMT 3.90885
TND 3.394561
TOP 2.615695
TRY 38.161322
TTD 7.585372
TWD 35.28057
TZS 3048.90309
UAH 45.967974
UGX 4125.289807
USD 1.116814
UYU 46.821075
UZS 14225.424679
VEF 4045718.043587
VES 41.120607
VND 27484.797006
VUV 132.590423
WST 3.124246
XAF 656.162155
XAG 0.035308
XAU 0.000421
XCD 3.018247
XDR 0.826043
XOF 657.249161
XPF 119.331742
YER 279.566552
ZAR 19.114316
ZMK 10052.671816
ZMW 29.530836
ZWL 359.613711
  • RBGPF

    64.7500

    64.75

    +100%

  • GSK

    -0.1900

    40.71

    -0.47%

  • RIO

    0.4800

    71.23

    +0.67%

  • BCC

    1.1800

    141.49

    +0.83%

  • CMSC

    0.0300

    25.14

    +0.12%

  • SCS

    0.0400

    13.25

    +0.3%

  • RELX

    -0.5300

    47.56

    -1.11%

  • RYCEF

    0.0100

    7.05

    +0.14%

  • BTI

    -0.2369

    36.84

    -0.64%

  • CMSD

    -0.0300

    25.08

    -0.12%

  • NGG

    -0.3300

    69.73

    -0.47%

  • AZN

    -0.5600

    77.62

    -0.72%

  • BCE

    0.3600

    35.19

    +1.02%

  • JRI

    0.1200

    13.58

    +0.88%

  • VOD

    0.0500

    10.09

    +0.5%

  • BP

    0.6300

    31.42

    +2.01%

What is Storm-1152, alleged top creator of fake Microsoft accounts?
What is Storm-1152, alleged top creator of fake Microsoft accounts? / Photo: Josep LAGO - AFP/File

What is Storm-1152, alleged top creator of fake Microsoft accounts?

Microsoft has seized the websites of a Vietnam-based group it alleges sold millions of fake accounts to cybercriminals who used them for ransomware attacks, identity theft and other scams around the world.

Text size:

The group, identified by Microsoft as Storm-1152, developed sophisticated tools to defeat the US tech giant's security features to set up fraudulent Outlook and Hotmail email accounts in bulk.

Who is in Storm-1152?

Storm-1152 was first detected in 2021. Arkose Labs, the cybersecurity firm that worked with Microsoft against the group, tracked it to Vietnam.

The leaders of the group are three Vietnam-based individuals, Duong Dinh Tu, Linh Van Nguyen and Tai Van Nguyen, Microsoft said in a statement on Wednesday. It is not clear if there are any other members.

AFP has asked the three for a response on email addresses listed in Microsoft's complaint against them in a US federal court last week.

AFP has also contacted Vietnamese authorities for comment.

How did they make millions of accounts so rapidly?

Storm-1152 developed automated software -- or "bots" -- to create fake accounts.

These bots defeated Microsoft's safeguards, such as the CAPTCHA puzzles users have to solve to prove they are human, the tech giant said in its court filing.

Storm-1152 is "the number one seller and creator of fraudulent Microsoft accounts", creating around 750 million to date, the company said Wednesday.

Microsoft's court filing included a screenshot of a Storm-1152 website that boasts the use of artificial intelligence against CAPTCHA.

The group created accounts "at a scale so large, fast, and efficient that it could have only been carried out through automated, machine-learning technology", Patrice Boffa, chief customer officer at Arkose Labs, said in a statement.

Who needs so many fake email accounts?

Storm-1152 pursued a model called "cybercrime-as-a-service" or CaaS, acting as a provider to other criminal groups, Microsoft and Arkose said.

With tech companies improving their detection and deletion of fake accounts, cyber attackers need huge amounts to carry out their operations.

"Instead of spending time trying to create thousands of fraudulent accounts, cybercriminals can simply purchase them from Storm-1152 and other groups," Microsoft's Amy Hogan-Burney said in a blog post.

Storm-1152 allegedly made millions of dollars from the operation.

What did Storm-1152's customers do with fake accounts?

The group's customers have used fake email accounts for a variety of crimes, according to Microsoft and Arkose Labs.

These include phishing attacks to either steal information or insert malware on devices.

Its customers have also used these accounts to install ransomware and demand payment from victims, according to Microsoft.

The highest-profile customer named in Microsoft's court filing is a group known as Octo Tempest, which has been linked to a wave of cybercrimes in recent years.

Octo Tempest recently launched ransomware attacks against Microsoft customers that "inflicted hundreds of millions of dollars of damage", the company said in its court filing, without naming the victims.

Google and X, formerly known as Twitter, have also been hit by Storm-1152 activities, Microsoft said in the filing.

Was it hard to find Storm-1152?

Unlike many cybercriminals that offer such services on the so-called dark web, hidden away from general users, Storm-1152's websites were on the open web.

It offered its services on at least two websites, according to Microsoft, and even had step-by-step user guides.

Duong Dinh Tu, one of the defendants, also had a YouTube channel with a video demonstration, and the group would edit the code for their anti-CAPTCHA software on GitHub -- a Microsoft-owned internet depository for software.

Microsoft said it also hired cybercrime experts to make undercover purchases of accounts and CAPTCHA-beating tools from Storm-1152 websites.

A US court allowed Microsoft to take control of the group's sites in response to the company's complaint last week.

The sites now say: "This Domain has been seized by Microsoft."

(H.Schneide--BBZ)