Also known as: FIN7, QBot, QuackBot, Pinkslipbot, APT28, Pawn Storm, Fancy Bear, Sednit, Project Spy, Cridex, U2DiskWatch, similar to Sliver, Cobalt Strike, consists of multiple components, control module, NoFive, Plat1, NetSupport RAT, Carbon Spider, Trickbot LLC, DEV-0230
Storm-0506 (DEV-0506) is a financially motivated cybercriminal group operating as a core affiliate within the Black Basta ransomware-as-a-service (RaaS) ecosystem, having switched from deploying Conti ransomware around April 2022. This actor's operational model is distinguished by its strategic reliance on a dynamic network of initial access brokers, showcasing a division of labor common in RaaS operations. Throughout its history, Storm-0506 has leveraged access obtained through various brokers: initially Storm-0450/0464 via Qakbot infections (pre-September 2023), then expanding to include Storm-1674 delivering DarkGate, Pikabot, and IcedID (September 2023), and later employing Storm-1674's Microsoft Teams vishing campaigns (October 2024) and Storm-0569's SEO poisoning leading to BATLOADER and Cobalt Strike (December 2023). Following successful initial compromise, Storm-0506 employs a range of post-exploitation tools, including Cobalt Strike Beacon, SystemBC, and Brute Ratel C4 backdoors, and notably, often utilizes command-and-control (C2) infrastructure established by Storm-0365, indicating close collaboration or shared resources. This actor is characterized by hands-on-keyboard activity, culminating in the deployment of Black Basta ransomware. A resurgence in activity observed in October 2024, directly linked to Storm-1674's vishing, underscores the ongoing and adaptive threat that Storm-0506 represents within the ransomware landscape.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm-0506 is a financially motivated cybercriminal group operating as a core affiliate within the Black Basta ransomware-as-a-service (RaaS) ecosystem. Originally deploying Conti ransomware, they transitioned to Black Basta in April 2022. They utilize a dynamic network of initial access brokers and exhibit hands-on-keyboard activity, making them a significant threat in the ransomware landscape.
Goals & Targeting
Storm-0506's primary motivation is financial gain through ransomware operations. They target sectors with high potential for payouts, including finance, healthcare, manufacturing, and critical infrastructure. Their targeting profile reflects a focus on organizations in regions where RaaS affiliates are active, leveraging initial access brokers to expand their reach.
Enhanced Description
Storm-0506 operates as a core affiliate within the Black Basta ransomware-as-a-service (RaaS) ecosystem. Initially deploying Conti ransomware, they transitioned to Black Basta in April 2022. Their operational model is characterized by strategic reliance on a network of initial access brokers, reflecting a division of labor common in RaaS operations. Storm-0506 has leveraged access obtained through various brokers: initially via Qakbot infections (pre-September 2023), then expanding to include Storm-1674 delivering DarkGate, Pikabot, and IcedID (September 2023), and later employing Storm-1674's Microsoft Teams vishing campaigns (October 2024) and Storm-0569's SEO poisoning leading to BATLOADER and Cobalt Strike (December 2023). Their post-exploitation toolkit includes Cobalt Strike Beacon, SystemBC, and Brute Ratel C4 backdoors. Notably, they often utilize command-and-control (C2) infrastructure established by Storm-0365, indicating close collaboration or shared resources. Following initial compromise, they deploy Black Basta ransomware directly. A resurgence in activity observed in October 2024, linked to Storm-1674's vishing campaigns, underscores their ongoing and adaptive threat within the ransomware landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-0506 has demonstrated a clear pattern of campaign activity, leveraging evolving methods such as vishing and SEO poisoning. Their use of multiple initial access brokers and affiliate networks highlights their adaptability and ability to scale operations quickly. Notable past operations include Conti ransomware campaigns before transitioning to Black Basta, as well as recent activity linked to Storm-1674's Microsoft Teams vishing campaigns in October 2024.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in their role as a core affiliate within the Black Basta RaaS ecosystem, based on linked intelligence and observed campaign patterns. Some gaps exist regarding the full extent of their infrastructure and exact sources of initial access.
Conti Ransomware
Imported from MISP event #255 (0319b483-5973-4932-91ea-5a44c2975b24).
May 16, 2021
TLP:CLEARNo observed data linked yet.
8
Techniques
40
Tools
1
Campaigns
40
IOCs
0
Observed Data
4
Tactics