Cyber Resilience

Threat actor · all actors

Storm-0784HACK-STORM-0784 hacktivist

🇮🇷 IR

aka Storm-0784, Storm-0784 (Microsoft cluster)

Last updated: 2026-08-20

0attributed CVEs
0ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

A Microsoft-tracked cluster operating under hacktivist branding against Israeli targets since 2023. Microsoft Threat Intelligence assesses the actor as Iran-aligned; listed here under the hacktivist persona used in claims, with the caveat that several vendors classify the activity as state-aligned cyber operation.

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

Microsoftweather-system names

Storm-0784

Unclassifiedno scheme matched

Storm-0784 (Microsoft cluster)

How we know this

Data origin
Curated overlay Hacktivist entry synthesised from public reporting — not a MITRE-tracked intrusion set.
Techniques
No ATT&CK techniques mapped.
Named victims
None on file.

Thin data: No ATT&CK techniques are mapped yet — the behavioural profile is empty.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

No techniques attributed.

Co-occurring actors

None.

Similar actors

Same nation-state