Microsoft has identified a cyber gang accused of creating malicious tools that are able to bypass artificial intelligence protection shields , creating a deepfake network of celebrities and other illegal content
See also: Bureau: Raises $30 million to combat Deepfakes

An updated complaint identifies individuals as Arian Yadegarnia from Iran, also known as “Fiz”, Alan Krysiak from the United Kingdom, also known as “Drago”, Ricky Yuen from Hong Kong, China, also known as “cg-dot”, and Phát Phùng Tấn from Vietnam, also known as “Askuri”.
The company reported today that these threat actors are part of an international cybercriminal gang known as Storm-2139.
According to Microsoft's research, the Storm-2139 criminal network is structured into three main categories: creators, providers, and users.
The creators developed tools that enabled the misuse of AI-based services. The providers packaged and distributed these illegal tools to end users. The users used them to create content that violated Microsoft's Acceptable Use Policy and Code of Conduct, often focusing on sexual imagery and celebrities.
See also: Surf Security adds Deepfake Detection tool to Enterprise Browser
The latest update concerns the company's lawsuit filed in December 2024 in the Eastern District of Virginia, with the aim of gathering more evidence about the criminal ring's in cyberspace.

A temporary restraining order and a preliminary injunction issued after the first filing allowed Microsoft to prevent the group from illegally using its services, taking down one of the main websites of the criminal infrastructure.
According to Microsoft, the seizure sparked controversy among members of Storm-2139, as they began to speculate about who the “John Does” referred to in the files were. In addition, Microsoft’s legal team received a flood of emails in which suspected members of Storm-2139 accused others of malicious activity.
See also: FIN7 gang hides Malware in AI “Deepnude” sites
To protect your personal data from threats related to deepfake networks, you can follow a few steps:
- Verify sources: Be wary of videos and audio that do not come from reliable sources.
- Understand the clues: Look for unusual files or small discrepancies in videos that may indicate editing.
- Stay informed: Staying up-to-date on the latest developments in deepfake technology can help you better identify and prevent potential threats.
- Use security software: Security tools and anti-malware programs can help detect and remove potential threats.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
