Also known as: DEV-1044
Storm-1044 has been identified as part of a cyber campaign in collaboration with Twisted Spider. They employ a strategic approach, targeting specific endpoints using an initial access trojan called DanaBot. Once they gain access, Storm-1044 initiates lateral movement through Remote Desktop Protocol sign-in attempts, passing control to Twisted Spider. Twisted Spider then compromises the endpoints by introducing the CACTUS ransomware. Microsoft has detected ongoing malvertising attacks involving Storm-1044, leading to the deployment of CACTUS ransomware.
Executive Summary
Storm-1044 is a cyber threat actor collaborating with Twisted Spider, targeting endpoints through DanaBot for initial access, lateral movement via RDP, and deploying CACTUS ransomware. Their malvertising campaigns distribute malware leading to ransomware deployment, detected by Microsoft.
Goals & Targeting
Storm-1044's primary goal is likely financial gain through ransomware activity. Targeting sectors with high payouts, such as finance and healthcare, they exploit human error and system vulnerabilities to compromise endpoints and deploy CACTUS ransomware.
Enhanced Description
Storm-1044 operates in collaboration with Twisted Spider, focusing on strategic cyberattacks using the DanaBot IAT for initial access. They employ lateral movement via RDP, enabling subsequent deployment of CACTUS ransomware by their partners. Their campaigns involve malvertising attacks detected by Microsoft, indicating significant malware distribution efforts.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-1044's attacks are part of an ongoing campaign, with collaborative efforts enhancing their operational reach. Targeting organizations via malvertising and IAT deployment, they have been detected by Microsoft but specific targets remain unclear.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Storm-1044's primary activity involving ransomware deployment and malvertising. Limited details on specific targets and TTPs beyond known data.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics