Also known as: DEV-1084
Storm-1084 is a threat actor that has been observed collaborating with the MuddyWater group. They have used the DarkBit persona to mask their involvement in targeted attacks. Storm-1084 has been linked to destructive actions, including the encryption of on-premise devices and deletion of cloud resources. They have been observed using tools such as Rport, Ligolo, and a customized PowerShell backdoor. The extent of their autonomy or collaboration with other Iranian threat actors is currently unclear.
Executive Summary
Storm-1084, also known as DEV-1084, is a suspected state-sponsored threat actor linked to the MuddyWater group. They are known for destructive activities such as encrypting on-premise devices and deleting cloud resources. Storm-1084 uses tools like Rport, Ligolo, and custom PowerShell backdoors, suggesting advanced capabilities likely targeting specific sectors with strategic intent.
Goals & Targeting
Storm-1084 likely aims to disrupt or destroy critical infrastructure and gather intelligence through destructive campaigns. Their collaboration with MuddyWater indicates possible alignment with broader Iranian cyber espionage activities targeting Middle Eastern governments and private entities.
Enhanced Description
Storm-1084 is a moderately sophisticated threat actor with links to the MuddyWater group and has been observed using DarkBit persona to hide their activities. Their primary methods include destructive actions like system encryption and resource deletion, along with employment of custom tools such as Rport remote access tool (RAT), Ligolo information stealer, and PowerShell backdoor. The group's collaboration with other Iranian threat actors is evident but the extent of their operational independence remains unclear. Storm-1084's targeting pattern suggests a focus on strategic sectors potentially aligned with state interests, though specific targets are not fully documented.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-1084 has been involved in campaigns aligned with MuddyWater group, targeting regions possibly in the Middle East or North Africa. Their operations involve long-term access and destructive payloads, suggesting a focus on destabilization or data destruction
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in assessment is moderate due to limited available intelligence. Key gaps include specific sectors targeted, exact geographic focus, and the extent of their operational autonomy
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics