SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

Storm-1567

❔ UnknownMotivation: financialLast active: 2026-08-10First seen: 2024-02-20G1024
6
linked CVEs
Also known as
AkiraPUNK SPIDERGOLD SAHARAMegazordHowling Scorpius
Targeted industries
Agriculture and Food ProductionBusiness ServicesConstructionConsumer ServicesEnergyFinancial ServicesHealthcareHospitality and TourismManufacturingNot FoundTechnologyTelecommunicationTransportation/Logistics
Targeted regions
ARAUCACHDEESFRGBITJPNJNLQCUS
Storm-1567 is the threat actor behind the Ransomware-as-a-Service Akira. They attacked Swedish organizations in March 2023. This ransomware utilizes the ChaCha encryption algorithm, PowerShell, and Windows Management Instrumentation (WMI). Microsoft's Defender for Endpoint successfully blocked a large-scale hacking campaign carried out by Storm-1567, highlighting the effectiveness of their security solution.
Source: misp_galaxy · Collected: 2026-08-10
⚡ Vulnerabilities & Exploits6 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2025-55182
suspected

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CVSS 10.0
KEVransomware
CVE-2024-55591
suspected

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

CVSS 9.8
KEVransomware
CVE-2024-40766
suspected

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

KEVransomware
CVE-2025-32433
suspected

Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.

KEV
CVE-2025-33073
suspected

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

KEV
CVE-2025-7771
suspected

🔍 Detection Coverage2 Sigma
Derived from linked CVEs — not a direct actor match
highvia CVE-2025-55182
Linux Suspicious Child Process from Node.js - React2Shell
linux
highvia CVE-2025-55182
Windows Suspicious Child Process from Node.js - React2Shell
windows
🧬 YaraComing soon
MITRE ATT&CK Techniques Used17 techniques
Across 13 tactics
🛰️ Infrastructure & IOCs0
No IOCs linked to this actor yet.
📰 Threat Intel Coverage4
Digest reports mentioning this actor (incl. aliases)
No Manners Here: The Ruthless Rise of The Gentlemen Ransomwarematched as Howling Scorpius2026-07-10
Tune In: The Future of AI-Powered Vulnerability Discoverymatched as PUNK SPIDER2026-05-01
Nowhere, man: The 2026 Active Adversary Reportmatched as Gold Sahara2026-02-24
Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacksmatched as Akira2025-10-31