Also known as: DEV-0381
Storm-0381 is a threat actor identified by Microsoft as a Russian cybercrime group. They are known for their use of malvertising to deploy Magniber, a type of ransomware.
Executive Summary
Storm-0381 is a Russian cybercrime group linked to distributing Magniber ransomware through malvertising campaigns. Known for targeting financial and healthcare sectors, they pose a significant threat due to their financially motivated activities.
Goals & Targeting
Storm-0381's primary goal is financial gain, achieved through large-scale ransomware campaigns targeting high-value industries such as finance and healthcare. Their focus on these sectors suggests a strategy to maximize the potential for ransom payments due to data sensitivity and critical operations.
Enhanced Description
Storm-0381 operates as a Russian cybercriminal group specializing in malvertising to deploy Magniber ransomware. Their campaigns typically involve infecting users via malicious ads, leveraging this method to distribute malware across various industries. The group has demonstrated persistence since first observed in late 2019, with ongoing activities primarily aimed at extracting financial gains from targeted sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-0381 has conducted prolonged campaigns since late 2019, focusing on EMEA regions. Their operations often involve multi-stage attacks beginning with malware distribution and culminating in ransomware deployment, targeting industries where data is critical and ransoms are likely.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is high in the group's association with Magniber but limited on specific campaign details due to the lack of comprehensive TTP documentation.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics