The Fort Worth Press - What is Storm-1152, alleged top creator of fake Microsoft accounts?

USD -
AED 3.67302
AFN 68.291665
ALL 93.057229
AMD 389.770539
ANG 1.808359
AOA 911.999622
ARS 1001.919444
AUD 1.544092
AWG 1.795
AZN 1.703104
BAM 1.855228
BBD 2.025868
BDT 119.90021
BGN 1.85709
BHD 0.376614
BIF 2963.296747
BMD 1
BND 1.345185
BOB 6.933055
BRL 5.796203
BSD 1.003315
BTN 84.297531
BWP 13.716757
BYN 3.283486
BYR 19600
BZD 2.022453
CAD 1.407425
CDF 2865.00031
CHF 0.88767
CLF 0.035506
CLP 979.709938
CNY 7.233902
CNH 7.240503
COP 4425.67
CRC 510.64839
CUC 1
CUP 26.5
CVE 104.59491
CZK 23.954978
DJF 178.66544
DKK 7.07361
DOP 60.456292
DZD 133.234044
EGP 49.302899
ERN 15
ETB 121.511455
EUR 0.94838
FJD 2.27595
FKP 0.789317
GBP 0.79132
GEL 2.734973
GGP 0.789317
GHS 16.027888
GIP 0.789317
GMD 71.000285
GNF 8646.941079
GTQ 7.74893
GYD 209.812896
HKD 7.784165
HNL 25.339847
HRK 7.133259
HTG 131.909727
HUF 386.359922
IDR 15839.3
ILS 3.749297
IMP 0.789317
INR 84.42825
IQD 1314.3429
IRR 42092.496279
ISK 137.610055
JEP 0.789317
JMD 159.351136
JOD 0.7091
JPY 154.760969
KES 129.929869
KGS 86.496657
KHR 4053.579729
KMF 466.575022
KPW 899.999621
KRW 1392.550147
KWD 0.30754
KYD 0.836179
KZT 498.615064
LAK 22046.736197
LBP 89848.180874
LKR 293.122747
LRD 184.608672
LSL 18.253487
LTL 2.95274
LVL 0.60489
LYD 4.900375
MAD 10.002609
MDL 18.230627
MGA 4667.201055
MKD 58.441866
MMK 3247.960992
MNT 3397.999946
MOP 8.045323
MRU 40.054641
MUR 47.210062
MVR 15.450134
MWK 1739.868711
MXN 20.342601
MYR 4.466497
MZN 63.902545
NAD 18.253747
NGN 1666.779868
NIO 36.921442
NOK 11.0727
NPR 134.880831
NZD 1.70441
OMR 0.38465
PAB 1.003296
PEN 3.808919
PGK 4.034511
PHP 58.72503
PKR 278.580996
PLN 4.092995
PYG 7828.648128
QAR 3.65762
RON 4.721202
RSD 110.989157
RUB 99.885908
RWF 1378.077124
SAR 3.755975
SBD 8.390419
SCR 13.839562
SDG 601.503045
SEK 10.965735
SGD 1.34174
SHP 0.789317
SLE 22.600719
SLL 20969.504736
SOS 573.447802
SRD 35.315503
STD 20697.981008
SVC 8.779169
SYP 2512.529858
SZL 18.247358
THB 34.737974
TJS 10.695389
TMT 3.51
TND 3.165498
TOP 2.342103
TRY 34.491635
TTD 6.812749
TWD 32.519502
TZS 2660.000224
UAH 41.44503
UGX 3682.325879
UYU 43.055121
UZS 12842.792233
VES 45.732015
VND 25375
VUV 118.722009
WST 2.791591
XAF 622.255635
XAG 0.03262
XAU 0.000386
XCD 2.70255
XDR 0.755845
XOF 622.229073
XPF 113.127366
YER 249.874979
ZAR 18.12535
ZMK 9001.198001
ZMW 27.546563
ZWL 321.999592
  • SCS

    -0.0400

    13.23

    -0.3%

  • BCC

    -0.2600

    140.09

    -0.19%

  • NGG

    0.3800

    62.75

    +0.61%

  • RBGPF

    61.8400

    61.84

    +100%

  • AZN

    -1.8100

    63.23

    -2.86%

  • BTI

    0.9000

    36.39

    +2.47%

  • RIO

    0.5500

    60.98

    +0.9%

  • GSK

    -0.6509

    33.35

    -1.95%

  • CMSC

    0.0200

    24.57

    +0.08%

  • CMSD

    0.0822

    24.44

    +0.34%

  • BCE

    -0.0200

    26.82

    -0.07%

  • RELX

    -1.5000

    44.45

    -3.37%

  • VOD

    0.0900

    8.77

    +1.03%

  • RYCEF

    0.0400

    6.82

    +0.59%

  • JRI

    0.0235

    13.1

    +0.18%

  • BP

    -0.0700

    28.98

    -0.24%

What is Storm-1152, alleged top creator of fake Microsoft accounts?
What is Storm-1152, alleged top creator of fake Microsoft accounts? / Photo: © AFP/File

What is Storm-1152, alleged top creator of fake Microsoft accounts?

Microsoft has seized the websites of a Vietnam-based group it alleges sold millions of fake accounts to cybercriminals who used them for ransomware attacks, identity theft and other scams around the world.

Text size:

The group, identified by Microsoft as Storm-1152, developed sophisticated tools to defeat the US tech giant's security features to set up fraudulent Outlook and Hotmail email accounts in bulk.

Who is in Storm-1152?

Storm-1152 was first detected in 2021. Arkose Labs, the cybersecurity firm that worked with Microsoft against the group, tracked it to Vietnam.

The leaders of the group are three Vietnam-based individuals, Duong Dinh Tu, Linh Van Nguyen and Tai Van Nguyen, Microsoft said in a statement on Wednesday. It is not clear if there are any other members.

AFP has asked the three for a response on email addresses listed in Microsoft's complaint against them in a US federal court last week.

AFP has also contacted Vietnamese authorities for comment.

How did they make millions of accounts so rapidly?

Storm-1152 developed automated software -- or "bots" -- to create fake accounts.

These bots defeated Microsoft's safeguards, such as the CAPTCHA puzzles users have to solve to prove they are human, the tech giant said in its court filing.

Storm-1152 is "the number one seller and creator of fraudulent Microsoft accounts", creating around 750 million to date, the company said Wednesday.

Microsoft's court filing included a screenshot of a Storm-1152 website that boasts the use of artificial intelligence against CAPTCHA.

The group created accounts "at a scale so large, fast, and efficient that it could have only been carried out through automated, machine-learning technology", Patrice Boffa, chief customer officer at Arkose Labs, said in a statement.

Who needs so many fake email accounts?

Storm-1152 pursued a model called "cybercrime-as-a-service" or CaaS, acting as a provider to other criminal groups, Microsoft and Arkose said.

With tech companies improving their detection and deletion of fake accounts, cyber attackers need huge amounts to carry out their operations.

"Instead of spending time trying to create thousands of fraudulent accounts, cybercriminals can simply purchase them from Storm-1152 and other groups," Microsoft's Amy Hogan-Burney said in a blog post.

Storm-1152 allegedly made millions of dollars from the operation.

What did Storm-1152's customers do with fake accounts?

The group's customers have used fake email accounts for a variety of crimes, according to Microsoft and Arkose Labs.

These include phishing attacks to either steal information or insert malware on devices.

Its customers have also used these accounts to install ransomware and demand payment from victims, according to Microsoft.

The highest-profile customer named in Microsoft's court filing is a group known as Octo Tempest, which has been linked to a wave of cybercrimes in recent years.

Octo Tempest recently launched ransomware attacks against Microsoft customers that "inflicted hundreds of millions of dollars of damage", the company said in its court filing, without naming the victims.

Google and X, formerly known as Twitter, have also been hit by Storm-1152 activities, Microsoft said in the filing.

Was it hard to find Storm-1152?

Unlike many cybercriminals that offer such services on the so-called dark web, hidden away from general users, Storm-1152's websites were on the open web.

It offered its services on at least two websites, according to Microsoft, and even had step-by-step user guides.

Duong Dinh Tu, one of the defendants, also had a YouTube channel with a video demonstration, and the group would edit the code for their anti-CAPTCHA software on GitHub -- a Microsoft-owned internet depository for software.

Microsoft said it also hired cybercrime experts to make undercover purchases of accounts and CAPTCHA-beating tools from Storm-1152 websites.

A US court allowed Microsoft to take control of the group's sites in response to the company's complaint last week.

The sites now say: "This Domain has been seized by Microsoft."

L.Holland--TFWP