Threat Intelligence / Actor / Storm-2372 / EvilTokens PhaaS Operators

Storm-2372 / EvilTokens PhaaS Operators

Nation: Russia · 1 tracked threat(s) · Categories: PHISHING

Also known as: Storm-2372, APT29, Cozy Bear, Midnight Blizzard, UTA0304, UTA0307, UNK_AcademicFlare, _eviltokensadmin_, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence