Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1044

Also known as: DEV-1044

Description

Storm-1044 has been identified as part of a cyber campaign in collaboration with Twisted Spider. They employ a strategic approach, targeting specific endpoints using an initial access trojan called DanaBot. Once they gain access, Storm-1044 initiates lateral movement through Remote Desktop Protocol sign-in attempts, passing control to Twisted Spider. Twisted Spider then compromises the endpoints by introducing the CACTUS ransomware. Microsoft has detected ongoing malvertising attacks involving Storm-1044, leading to the deployment of CACTUS ransomware.

AI Analysis

· 1 week ago

Executive Summary

Storm-1044 is a cyber threat actor collaborating with Twisted Spider, targeting endpoints through DanaBot for initial access, lateral movement via RDP, and deploying CACTUS ransomware. Their malvertising campaigns distribute malware leading to ransomware deployment, detected by Microsoft.

Goals & Targeting

Storm-1044's primary goal is likely financial gain through ransomware activity. Targeting sectors with high payouts, such as finance and healthcare, they exploit human error and system vulnerabilities to compromise endpoints and deploy CACTUS ransomware.

Enhanced Description

Storm-1044 operates in collaboration with Twisted Spider, focusing on strategic cyberattacks using the DanaBot IAT for initial access. They employ lateral movement via RDP, enabling subsequent deployment of CACTUS ransomware by their partners. Their campaigns involve malvertising attacks detected by Microsoft, indicating significant malware distribution efforts.

Key Capabilities

  • Initial Access Trojan (IAT): DanaBot
  • Lateral Movement via RDP Sign-ins
  • CACTUS Ransomware Deployment
  • Malvertising Campaigns

MITRE ATT&CK Tactics

Execution
Lateral Movement
Defense Evasion

ATT&CK Techniques

T1021.003
T1097
T1566

Software / Tooling

DanaBot
CACTUS Ransomware
Malvertising Infrastructure

Campaigns & Victims

Storm-1044's attacks are part of an ongoing campaign, with collaborative efforts enhancing their operational reach. Targeting organizations via malvertising and IAT deployment, they have been detected by Microsoft but specific targets remain unclear.

IOC Patterns

  • Malicious links in malvertising campaigns
  • DanaBot infection signatures on endpoints
  • CACTUS ransomware payloads detection
  • RDP sign-in attempts from high-numbered ports

Recommended Actions

  • Monitor and restrict external RDP access points.
  • Enhance ad network monitoring for suspicious domains.
  • Implement multi-layer security defenses around endpoints.
  • Regularly test backup processes to ensure data integrity.
  • Educate users on avoiding malicious phishing links.
  • Conduct proactive threat hunting for known IATs and ransomware.

Suggested Tags

APT
ransomware
collaborative attacks

Confidence Assessment

High confidence in Storm-1044's primary activity involving ransomware deployment and malvertising. Limited details on specific targets and TTPs beyond known data.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
collaborative attacks

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.