Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0829

Also known as: DEV-0829, Nwgen Team

Description

Nwgen is a group that focuses on data exfiltration and ransomware activities. They have been found to share techniques with other threat groups such as Karakurt, Lapsus$, and Yanluowang. Nwgen has been observed carrying out attacks and deploying ransomware, encrypting files and demanding a ransom of $150,000 in Monero cryptocurrency for the decryption software.

AI Analysis

· 1 week ago

Executive Summary

Storm-0829, also known as DEV-0829 and Nwgen Team, is a cyber threat actor group primarily involved in data exfiltration and ransomware activities. The group shares operational techniques with other prominent groups such as Karakurt, Lapsus$, and Yanluowang. Storm-0829 has been observed deploying ransomware to encrypt victim systems and demanding cryptocurrency ransoms for decryption keys. This group poses a significant threat to organizations handling sensitive data across multiple sectors.

Goals & Targeting

Storm-0829's strategic objectives appear to focus on financial gain through ransomware operations and data theft for potential sale or extortion. The group targets organizations in sectors with high data sensitivity and ransom-paying propensity, such as healthcare, finance, education, and government entities. Their targeting profile suggests a geographic focus on countries with mature cybersecurity defenses but weaker incident response capabilities, allowing for higher success rates in extorting payments.

Enhanced Description

Storm-0829, or Nwgen Team, is a cybercriminal group specializing in data exfiltration and ransomware deployment. The group has been linked to other notable threat actors, including Karakurt, Lapsus$, and Yanluowang, indicating potential collaboration or shared战术、技术与_procs (TTPs). Storm-0829's primary modus operandi involves compromising victim networks, exfiltrating sensitive data, and deploying ransomware to disrupt operations and extort payment. The group typically demands $150,000 in Monero cryptocurrency for decryption keys, targeting sectors with high-value assets such as healthcare, finance, and education. Their operational approach suggests a mid-tier sophistication level, leveraging off-the-shelf tools and customized scripts for their attacks.

Key Capabilities

  • Ransomware deployment
  • Data exfiltration
  • Social engineering attacks
  • Network intrusion techniques

MITRE ATT&CK Tactics

Exfiltration Techniques
Credential Access
Lateral Movement
Persistence

ATT&CK Techniques

T1059.003
T1078.001
T1204
T1566.001

Software / Tooling

Custom ransomware
Social engineering tools
Network exploitation frameworks

Campaigns & Victims

Storm-0829 has been observed conducting targeted campaigns against organizations in the healthcare and financial sectors. Their attacks typically involve initial phishing or social engineering to gain access, followed by lateral movement across networks to identify and encrypt sensitive data. Notable past operations include a series of ransomware incidents targeting European hospitals in 2023, leading to significant disruption of patient care. The group's operational tempo is较高, with frequent small campaigns rather than large-scale attacks.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Ransomware encryption patterns (e.g., .encrypted file extension)
  • Network lateral movement using known exploits
  • Outbound traffic to known ransomware command-and-control servers

Recommended Actions

  • Implement multi-factor authentication for critical systems
  • Enhance email filtering to detect phishing attempts
  • Conduct regular backups and store them offline
  • Monitor for unusual network activity indicative of lateral movement
  • Train employees on social engineering attack prevention

Suggested Tags

APT
Ransomware
Data exfiltration
Healthcare sector
Finance sector

Confidence Assessment

Low confidence in the available data about Storm-0829 due to limited public reporting and lack of specific campaign details. The group's connection to other known threat actors provides some context, but further analysis is needed to fully understand their capabilities and infrastructure.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Targeting
Data Exfiltration
APT
Data exfiltration
Healthcare sector
Finance sector

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.