Storm-3121 and Storm-3032 Cloud Intrusion Campaigns
Score: 9/10

Storm-3121 and Storm-3032 Cloud Intrusion Campaigns

Threat actors Storm-3121 and Storm-3032 utilize passkey-themed social engineering and AiTM phishing to compromise Microsoft cloud identities for automated data exfiltration via Microsoft Graph.

Executive Summary

Since May 2026, Microsoft has tracked sophisticated cloud intrusions attributed to a range of actors including Storm-3121 (linked to ShinyHunters and Falcon extortion) and Storm-3032 (a splinter of BlackFile operating under the Helix brand). The campaign leverages high-fidelity social engineering, including vishing and SMS, to lure victims into completing Adversary-in-the-Middle (AiTM) or device-code authentication flows under the guise of mandatory passkey or SSO updates.

Technically, the actors follow a structured lifecycle: identity compromise, MFA persistence through unauthorized device registration, extensive tenant reconnaissance via Microsoft Graph, and automated data collection from SharePoint, OneDrive, and Exchange. The actors often rotate infrastructure and use separate IP addresses for different attack stages to evade traditional network-based detection, preferring a measured pace of exfiltration to blend with legitimate enterprise traffic.

The business impact is severe, involving the potential exfiltration of sensitive organizational data, email correspondence, and internal documentation. Affected sectors include IT services, consumer goods, real estate, and discrete manufacturing, primarily in the U.S. Organizations are urged to move toward phishing-resistant MFA and monitor for specific behavioral sequences in cloud audit logs.

Key Details

Threat Name

Storm-3121 and Storm-3032 Passkey Phishing

Affects

—

Adversary

Storm-3121 Other Adversaries and Aliases: Storm-3032; BlackFile group; UNC6671; ShinyHunters; Falcon; BlackFile; Helix

Malware/Tools

python-httpx, Helix, Falcon

Report Score

9out of 10
Quality Score
Excellent
IOC Quality7
TTP Details9
Detection Guidance9
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources