Storm-0900 Hackers Leveraging Parking Ticket and Medical Test Themes in Massive Phishing Attack
## Cybersecurity: Storm-0900 Phishing Campaign Overview
Cybersecurity: Storm-0900 Phishing Campaign Overview
On Wed, Nov 26, 2025, a sophisticated phishing campaign was launched by the threat actor Storm-0900, targeting users across the United States. This operation was detected and blocked by Microsoft Threat Intelligence. The campaign involved tens of thousands of emails designed to exploit the holiday period for malicious purposes.
The phishing campaign utilized two primary social engineering themes: fake parking ticket notifications and fraudulent medical test results. These themes were strategically used to exploit the Thanksgiving period, creating a false sense of urgency and credibility that increased user interaction.
The phishing emails contained URLs leading to an attacker-controlled landing page on the domain permit-service[.]top. These pages included interactive elements such as CAPTCHA sliders to further deceive users and bypass security measures. This step was intended to validate the user's interaction capability in preparation for malware deployment.
The phishing scheme ultimately led to the deployment of XWorm, a modular remote access malware. XWorm's architecture allows threat actors to load various plugins to perform diverse tasks on compromised devices. Once installed, XWorm facilitates remote access, enabling attackers to deploy additional malware, extract sensitive data, and maintain persistence on victim systems.
On Wed, Nov 26, 2025, a sophisticated phishing campaign was launched by the threat actor Storm-0900, targeting users across the United States.
The malware communicates with command-and-control infrastructure, allowing attackers to issue remote commands and exfiltrate information from compromised machines.
Microsoft employed a multi-layered defense approach to disrupt this campaign, utilizing email filtering technologies, endpoint protections, and threat intelligence-based preemptive blocking of attacker infrastructure. This strategy effectively prevented most phishing emails from reaching intended targets and blocked access to malicious domains.
Organizations are advised to remain vigilant against unexpected communications referencing urgent matters, particularly during holiday periods when social engineering attempts are more frequent. Implementing robust email security controls is crucial to mitigating such threats.
Based on reporting by Cyber Security News.
