Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1674

Description

Storm-1674 is an access broker known for using tools based on the publicly available TeamsPhisher tool to distribute DarkGate malware. Storm-1674 campaigns have typically relied on phishing lures sent over Teams with malicious attachments, such as ZIP files containing a LNK file that ultimately drops DarkGate and Pikabot. In September 2023, Microsoft observed handoffs from Storm-1674 to ransomware operators that have led to Black Basta ransomware deployment.

AI Analysis

· 1 week ago

Executive Summary

Storm-1674 is an access broker leveraging phishing campaigns to distribute DarkGate malware, often through malicious Teams messages with ZIP attachments containing LNK files. Their recent activity includes handoffs to ransomware operators deploying Black Basta, indicating a shift towards more direct financial gain.

Goals & Targeting

Storm-1674's primary objective is likely financial gain through access brokering and facilitating ransomware deployments. They target sectors with valuable data or infrastructure, such as healthcare, education, and technology, particularly focusing on English-speaking regions due to the use of Teams communication channels. Their targeting profile suggests they seek high-value victims that can be exploited for long-term access or direct financial gain through ransomware.

Enhanced Description

Storm-1674 operates as an access broker specializing in phishing campaigns that exploit Microsoft Teams communication channels. They are known to distribute DarkGate malware, often through malicious attachments such as ZIP files containing LNK files that execute the payload once opened by victims. This approach has been observed in multiple campaigns targeting organizations globally. In September 2023, Storm-1674 facilitated a handoff between an access broker and ransomware operators, leading to the deployment of Black Basta ransomware. Their operational focus appears to be on compromising systems with potential value for ransomware groups, suggesting a strategic partnership model in their attacks.

Key Capabilities

  • Phishing campaigns using Microsoft Teams as a communication vector
  • Deployment of DarkGate malware via malicious LNK files
  • Handoffs with ransomware operators for financially motivated attacks
  • Use of publicly available tools like TeamsPhisher for phishing

MITRE ATT&CK Tactics

Credential Access
Exfiltration

ATT&CK Techniques

T1566.002

Software / Tooling

TeamsPhisher-based tools
DarkGate malware
Pikabot
Black Basta ransomware

Campaigns & Victims

Storm-1674 has demonstrated campaign patterns involving phishing over Teams, with a notable instance in September 2023 where they facilitated Black Basta deployment. Their victims have been observed primarily in sectors with high data value, such as healthcare and education. The group appears to maintain operational persistence while evolving their strategies to align with ransomware operators' demands.

IOC Patterns

  • Phishing messages sent via Microsoft Teams requesting verification of documents or action
  • ZIP file attachments containing LNK files
  • Use of HTTP/DNS communication channels for command-and-control (C2)
  • Inclusion of DarkGate and Pikabot malware

Recommended Actions

  • Monitor Microsoft Teams communications for suspicious phishing attempts related to document verification.
  • Implement endpoint detection rules to flag execution of LNK files outside expected workflows.
  • Conduct regular phishing awareness training among employees to mitigate social engineering risks.
  • Review and update ZIP file handling policies to minimize exposure to malicious payloads.

Suggested Tags

Access Brokerage
Ransomware
Malware
Phishing

Confidence Assessment

Low confidence due to limited details on Storm-1674's origins and broader objectives. While recent activity indicates a shift towards ransomware partnerships, further intelligence is needed to fully understand their operational scope and long-term goals.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Phishing
Access Brokerage
Malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.