SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

Storm-1567

❔ UnknownMotivation: financialLast active: 2026-09-23First seen: 2024-02-20G1024 ↗
6
linked CVEs
Also known as
AkiraPUNK SPIDERGOLD SAHARAMegazordHowling Scorpius
Targeted industries
Agriculture and Food ProductionBusiness ServicesConstructionConsumer ServicesEnergyFinancial ServicesHealthcareHospitality and TourismManufacturingNot FoundTechnologyTelecommunicationTransportation/Logistics
Targeted regions
ARAUCACHDEESFRGBITJPNJNLQCUS
Storm-1567 is the threat actor behind the Ransomware-as-a-Service Akira. They attacked Swedish organizations in March 2023. This ransomware utilizes the ChaCha encryption algorithm, PowerShell, and Windows Management Instrumentation (WMI). Microsoft's Defender for Endpoint successfully blocked a large-scale hacking campaign carried out by Storm-1567, highlighting the effectiveness of their security solution.
Source: misp_galaxy · Collected: 2026-09-24
⚡ Vulnerabilities & Exploits6 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2025-55182
suspected

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CVSS 10.0
KEVransomware
CVE-2024-40766
suspected

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CVSS 9.8
KEVransomware
CVE-2024-55591
suspected

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

CVSS 9.8
KEVransomware
CVE-2025-32433
suspected

Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.

KEV
CVE-2025-33073
suspected

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

KEV
CVE-2025-7771
suspected

—

🔍 Detection Coverage2 Sigma
Derived from linked CVEs — not a direct actor match
highvia CVE-2025-55182
Linux Suspicious Child Process from Node.js - React2Shell
linux
highvia CVE-2025-55182
Windows Suspicious Child Process from Node.js - React2Shell
windows
🧬 YaraComing soon
MITRE ATT&CK Techniques Used17 techniques
Across 13 tactics
🛰️ Infrastructure & IOCs5
md561a1ad1b6a028a1833c85e6544383999—2026-09-11
sha256e2356c742c74cce5c6b6100162d0071a3f71e2fed2ed895c2011061a95b3299a—2026-09-11
sha1bb6f97878c8cbf762d69717b3480658fe9157ff0—2026-09-11
sha256414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56—2026-09-11
ip72.23.77.35—2026-08-13
📰 Threat Intel Coverage4
Digest reports mentioning this actor (incl. aliases)
No Manners Here: The Ruthless Rise of The Gentlemen Ransomwarematched as Howling Scorpius2026-07-10
Tune In: The Future of AI-Powered Vulnerability Discoverymatched as PUNK SPIDER2026-05-01
Nowhere, man: The 2026 Active Adversary Reportmatched as Gold Sahara2026-02-24
Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacksmatched as Akira2025-10-31