Threadlinqs IntelligenceStart free

Threat actorRussia (GREYVIBE nexus)Tracked since 2026-06

Storm-1167

Also known as:GreyVibeTycoon 2FA operators

As of 2026-08-04, Storm-1167 is a Russia (GREYVIBE nexus)-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, phishing. Also known as GreyVibe, Tycoon 2FA operators. ATT&CK coverage spans 51 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1539 (Steal Web Session Cookie), T1557 (Adversary-in-the-Middle), T1027 (Obfuscated Files or Information).

Tracked threats
33 high
First seen
2026-06-23
Last seen
2026-08-04
ATT&CK techniques
51across 3 of 3 threats
Related CVEs
0None referenced
Attribution
Russia (GREYVIBE nexus)Nation or origin
Nation: Russia (GREYVIBE nexus) · 3 tracked threat(s) · Categories: THREAT_INTEL, PHISHING

Activity timeline

Storm-1167 appears in 3 tracked threats between and ; the busiest month was 2026-06 with 1 report.

ATT&CK techniques observed

51 techniques observed across 3 of 3 tracked threats · Credential Access (8), Resource Development (7), Stealth (formerly Defense Evasion) (7), Initial Access (5), Collection (4), Command and Control (4)
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 3 of 3 tracked threats
  • T1557 Adversary-in-the-Middle — Credential Accessobserved in 3 of 3 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1056 Input Capture — Credential Accessobserved in 2 of 3 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 2 of 3 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats
  • T1114 Email Collection — Collectionobserved in 2 of 3 tracked threats
  • T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1566.002 Spearphishing Link — Initial Accessobserved in 2 of 3 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 2 of 3 tracked threats
  • T1586 Compromise Accounts — Resource Developmentobserved in 2 of 3 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
  • T1056.003 Web Portal Capture — Credential Accessobserved in 1 of 3 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 1 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 1 of 3 tracked threats

Tracked threats