You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Update threat actor table with new entries and links
Added Daffodil Gust, Storm-0249, and Storm-1607 to the threat actor table. Updated Storm-0501 with a new blog link and revised the ms.date field. These changes reflect recent disclosures and provide up-to-date references for tracking threat actor activity.
|Storm-0230|Group in development|WIZARD SPIDER, Conti Team 1|
152
153
|Storm-0247|China|ToddyCat, Websiic|
154
+
|[Storm-0249](https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/)| Group in development ||
153
155
|Storm-0252|Group in development|CHATTY SPIDER|
154
156
|Storm-0288|Group in development|FIN8|
155
157
|Storm-0302|Group in development|NARWHAL SPIDER, TA544|
156
158
|[Storm-0408](https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/)|Group in development||
157
159
|[Storm-0485](https://www.microsoft.com/en-us/security/blog/2025/05/29/defending-against-evolving-identity-attack-techniques/)|Group in development||
|[Storm-1607](https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/)| Group in development ||
0 commit comments