FlagThis
← Threat Actors
/
China
/
Storm-1175
DOSSIER // STORM-1175
Storm-1175
ACTIVE CAMPAIGN TRACKED
▲ High Threat
China
Primary Aliases:
No secondary vendor aliases recorded.
Sponsor / State Affiliation
Chinese Government (State-sponsored)
Primary Motivation
Espionage and intelligence gathering
Active Timeline
Unknown – Present
Confidence Rating
90% (Grounded)
CVE-2023-23397 Exploitation Campaign
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(1)
CVE-2023-23397
Outlook NTLM Relay
CVSS 9.8
KEV
EPSS 92.0%
📋 Copy CSV
Tenable Nessus
Qualys / Wiz
🎯 Target Sectors & Focus
Government Agencies
Defense Industrial Base
Telecommunications
Information Technology
High-value individual email accounts
🛡️ MITRE ATT&CK® Attack Lifecycle
(5 TTPs)
📥 Download Navigator JSON
All Stages
5
Initial Access
2
Operational Techniques
3
Initial Access
2
T1566.001
Spearphishing Attachment
↗
T1078
Valid Accounts
↗
Operational Techniques
3
T1557.001
T1557.001 (Adversary-in-the-Middle: NTLM Relay)
↗
T1555
T1555 (Credentials from Password Stores)
↗
T1000
Exploitation of CVE-2023-23397
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Adversary Rosetta Stone // Storm-1175
×
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD