Assessed by Microsoft as a Gaza-based threat actor working to further the interests of Hamas (the de facto governing authority in the Gaza Strip). Attribution rests on victimology (targets are entities perceived as hostile to Hamas) rather than disclosed technical linkage. The 'Storm-####' designation is Microsoft's own convention for a cluster in development / temporary group with uncertain or not-yet-consolidated attribution, so the Hamas alignment should be read as a Microsoft assessment, not a settled multi-source consensus. Confidence: low-to-medium (single primary source, plausible and internally consistent).
Origin
Palestinian Territories (Gaza Strip)
First seen
2023
Last active
2023
Motivation
Espionage / intelligence collection aligned with Hamas geopolitical interests, targeting organizations and factions perceived as hostile to Hamas.
Attribution confidence
medium
MENA targeting
Israel
Sectors
Energy, defense, telecommunications
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Israel (Energy, defense, telecommunications sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
→Phishing: Spearphishing via ServicetechniqueATT&CK mapping
→Acquire Infrastructure: Web ServicestechniqueATT&CK mapping
→Establish Accounts: Social Media Accountstechnique
Observed techniques
7 distinct
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
MDDR 2023: backdoors carried a configuration allowing the group to dynamically update C2 infrastructure hosted on Google Drive, to stay ahead of static network-based defenses.
MDDR 2023: personas used to 'deliver malware to employees'; execution relies on the social-engineered target running the delivered backdoor (specific file type not reported).
MDDR 2023: Storm-1133 also targeted third-party organizations with public ties to Israeli targets of interest (and entities loyal to Fatah); assessed as third-party pivoting, exploitation of the relationship itself is not explicitly detailed.
Use of Google Drive to host and dynamically update C2 configuration (MDDR 2023) implies the group provisioned legitimate cloud web-service accounts as attacker infrastructure.
Microsoft Digital Defense Report 2023: Storm-1133 created fake LinkedIn profiles masquerading as Israeli HR managers, project coordinators, and software developers.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Storm-1133's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 4 techniques
Advanced Anti-Phishing T1566partialAnti-SpoofingT1566significantMultifactor AuthenticationT1566partialRole Based Access ControlT1199partialAntimalwareT1204significantAntimalwareT1204.002significantAntimalwareT1566significantAnti-PhishingT1566significantAntiSpamT1566significant
Defensive techniques that counter Storm-1133's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.