Storm-1674 is an access broker known for using tools based on the publicly available TeamsPhisher tool to distribute DarkGate malware. Storm-1674 campaigns have typically relied on phishing lures sent over Teams with malicious attachments, such as ZIP files containing a LNK file that ultimately drops DarkGate and Pikabot. In September 2023, Microsoft observed handoffs from Storm-1674 to ransomware operators that have led to Black Basta ransomware deployment.
Executive Summary
Storm-1674 is an access broker leveraging phishing campaigns to distribute DarkGate malware, often through malicious Teams messages with ZIP attachments containing LNK files. Their recent activity includes handoffs to ransomware operators deploying Black Basta, indicating a shift towards more direct financial gain.
Goals & Targeting
Storm-1674's primary objective is likely financial gain through access brokering and facilitating ransomware deployments. They target sectors with valuable data or infrastructure, such as healthcare, education, and technology, particularly focusing on English-speaking regions due to the use of Teams communication channels. Their targeting profile suggests they seek high-value victims that can be exploited for long-term access or direct financial gain through ransomware.
Enhanced Description
Storm-1674 operates as an access broker specializing in phishing campaigns that exploit Microsoft Teams communication channels. They are known to distribute DarkGate malware, often through malicious attachments such as ZIP files containing LNK files that execute the payload once opened by victims. This approach has been observed in multiple campaigns targeting organizations globally. In September 2023, Storm-1674 facilitated a handoff between an access broker and ransomware operators, leading to the deployment of Black Basta ransomware. Their operational focus appears to be on compromising systems with potential value for ransomware groups, suggesting a strategic partnership model in their attacks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-1674 has demonstrated campaign patterns involving phishing over Teams, with a notable instance in September 2023 where they facilitated Black Basta deployment. Their victims have been observed primarily in sectors with high data value, such as healthcare and education. The group appears to maintain operational persistence while evolving their strategies to align with ransomware operators' demands.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence due to limited details on Storm-1674's origins and broader objectives. While recent activity indicates a shift towards ransomware partnerships, further intelligence is needed to fully understand their operational scope and long-term goals.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics