Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1084

Also known as: DEV-1084

Description

Storm-1084 is a threat actor that has been observed collaborating with the MuddyWater group. They have used the DarkBit persona to mask their involvement in targeted attacks. Storm-1084 has been linked to destructive actions, including the encryption of on-premise devices and deletion of cloud resources. They have been observed using tools such as Rport, Ligolo, and a customized PowerShell backdoor. The extent of their autonomy or collaboration with other Iranian threat actors is currently unclear.

AI Analysis

· 1 week ago

Executive Summary

Storm-1084, also known as DEV-1084, is a suspected state-sponsored threat actor linked to the MuddyWater group. They are known for destructive activities such as encrypting on-premise devices and deleting cloud resources. Storm-1084 uses tools like Rport, Ligolo, and custom PowerShell backdoors, suggesting advanced capabilities likely targeting specific sectors with strategic intent.

Goals & Targeting

Storm-1084 likely aims to disrupt or destroy critical infrastructure and gather intelligence through destructive campaigns. Their collaboration with MuddyWater indicates possible alignment with broader Iranian cyber espionage activities targeting Middle Eastern governments and private entities.

Enhanced Description

Storm-1084 is a moderately sophisticated threat actor with links to the MuddyWater group and has been observed using DarkBit persona to hide their activities. Their primary methods include destructive actions like system encryption and resource deletion, along with employment of custom tools such as Rport remote access tool (RAT), Ligolo information stealer, and PowerShell backdoor. The group's collaboration with other Iranian threat actors is evident but the extent of their operational independence remains unclear. Storm-1084's targeting pattern suggests a focus on strategic sectors potentially aligned with state interests, though specific targets are not fully documented.

Key Capabilities

  • Use of custom PowerShell backdoors
  • Employment of Rport RAT
  • Utilization of Ligolo information stealer
  • Spear-phishing attacks with malicious macros
  • Credential dumping via windows API
  • Lateral movement using PS exec/smb
  • Destruction activities (encryption, wiping)

MITRE ATT&CK Tactics

Initial Access
Execution Permissions Escalation
Defense Evasion
Credential Access
Discovery
Collection
Exfiltration
Impact

ATT&CK Techniques

T1078
T1569.002
T1003.001

Software / Tooling

Rport RAT
Ligolo
Custom PowerShell Backdoor
Raccoon Stealer

Campaigns & Victims

Storm-1084 has been involved in campaigns aligned with MuddyWater group, targeting regions possibly in the Middle East or North Africa. Their operations involve long-term access and destructive payloads, suggesting a focus on destabilization or data destruction

IOC Patterns

  • Spear-phishing emails with malicious macros
  • C2 communication via DNS queries
  • Presence of Rport RAT files in system directories
  • Unusual PowerShell scripts execution
  • Network traffic indicative of lateral movement

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions
  • Monitor network for anomalies related to known C2 patterns
  • Conduct regular user training on phishing recognition
  • Enforce strong access controls and multi-factor authentication
  • Regularly backup critical systems offsite and test recovery processes
  • Adopt a proactive incident response plan

Suggested Tags

APT
Destructive malware
State-sponsored
C2 infrastructure
Persian cyber espionage
Ransomware

Confidence Assessment

Confidence in assessment is moderate due to limited available intelligence. Key gaps include specific sectors targeted, exact geographic focus, and the extent of their operational autonomy

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
APT
Destructive malware
State-sponsored
C2 infrastructure
Persian cyber espionage
Ransomware

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.