Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0381

Also known as: DEV-0381

Description

Storm-0381 is a threat actor identified by Microsoft as a Russian cybercrime group. They are known for their use of malvertising to deploy Magniber, a type of ransomware.

AI Analysis

· 1 week ago

Executive Summary

Storm-0381 is a Russian cybercrime group linked to distributing Magniber ransomware through malvertising campaigns. Known for targeting financial and healthcare sectors, they pose a significant threat due to their financially motivated activities.

Goals & Targeting

Storm-0381's primary goal is financial gain, achieved through large-scale ransomware campaigns targeting high-value industries such as finance and healthcare. Their focus on these sectors suggests a strategy to maximize the potential for ransom payments due to data sensitivity and critical operations.

Enhanced Description

Storm-0381 operates as a Russian cybercriminal group specializing in malvertising to deploy Magniber ransomware. Their campaigns typically involve infecting users via malicious ads, leveraging this method to distribute malware across various industries. The group has demonstrated persistence since first observed in late 2019, with ongoing activities primarily aimed at extracting financial gains from targeted sectors.

Key Capabilities

  • Malvertising campaigns
  • Magniber ransomware deployment
  • Use of TrickBot and BazarLoader for initial infections

MITRE ATT&CK Tactics

Initial Access
Execution
Impact

ATT&CK Techniques

T1055
T1204
T1493.001

Software / Tooling

Magniber Ransomware
TrickBot
BazarLoader

Campaigns & Victims

Storm-0381 has conducted prolonged campaigns since late 2019, focusing on EMEA regions. Their operations often involve multi-stage attacks beginning with malware distribution and culminating in ransomware deployment, targeting industries where data is critical and ransoms are likely.

IOC Patterns

  • Malicious ad campaigns delivering Magniber
  • Hosting domains used for malvertising campaigns
  • Communication channels using HTTP(S) or DGA techniques

Recommended Actions

  • Implement ad blockers to filter malicious ads
  • Monitor network traffic for signs of suspicious scripts and domains
  • Patch systems regularly and maintain offline backups

Suggested Tags

Ransomware
Cyber-Crime
Malware
Finance

Confidence Assessment

Confidence is high in the group's association with Magniber but limited on specific campaign details due to the lack of comprehensive TTP documentation.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Cyber-Crime
Malware
Finance

Details

Type
Unknown
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.