Activity timeline
Storm-2992 appears in 2 tracked threats between and ; the busiest month was 2026-09 with 1 report.
ATT&CK techniques observed
- T1087.004 Cloud Account — Discoveryobserved in 2 of 2 tracked threats
- T1098.005 Device Registration — Persistenceobserved in 2 of 2 tracked threats
- T1114.002 Remote Email Collection — Collectionobserved in 2 of 2 tracked threats
- T1204.001 Malicious Link — Executionobserved in 2 of 2 tracked threats
- T1528 Steal Application Access Token — Credential Accessobserved in 2 of 2 tracked threats
- T1534 Internal Spearphishing — Lateral Movementobserved in 2 of 2 tracked threats
- T1550.001 Application Access Token — Lateral Movementobserved in 2 of 2 tracked threats
- T1566.002 Spearphishing Link — Initial Accessobserved in 2 of 2 tracked threats
- T1583.006 Acquire Infrastructure: Web Services — Resource Developmentobserved in 2 of 2 tracked threats
- T1657 Financial Theft — Impactobserved in 2 of 2 tracked threats
- T1684.001 Impersonation — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1114.003 Email Forwarding Rule — Collectionobserved in 1 of 2 tracked threats
- T1119 Automated Collection — Collectionobserved in 1 of 2 tracked threats
- T1187 Forced Authentication — Credential Accessobserved in 1 of 2 tracked threats
- T1213.002 Sharepoint — Collectionobserved in 1 of 2 tracked threats