Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0506

Also known as: FIN7, QBot, QuackBot, Pinkslipbot, APT28, Pawn Storm, Fancy Bear, Sednit, Project Spy, Cridex, U2DiskWatch, similar to Sliver, Cobalt Strike, consists of multiple components, control module, NoFive, Plat1, NetSupport RAT, Carbon Spider, Trickbot LLC, DEV-0230

Description

Storm-0506 (DEV-0506) is a financially motivated cybercriminal group operating as a core affiliate within the Black Basta ransomware-as-a-service (RaaS) ecosystem, having switched from deploying Conti ransomware around April 2022. This actor's operational model is distinguished by its strategic reliance on a dynamic network of initial access brokers, showcasing a division of labor common in RaaS operations. Throughout its history, Storm-0506 has leveraged access obtained through various brokers: initially Storm-0450/0464 via Qakbot infections (pre-September 2023), then expanding to include Storm-1674 delivering DarkGate, Pikabot, and IcedID (September 2023), and later employing Storm-1674's Microsoft Teams vishing campaigns (October 2024) and Storm-0569's SEO poisoning leading to BATLOADER and Cobalt Strike (December 2023). Following successful initial compromise, Storm-0506 employs a range of post-exploitation tools, including Cobalt Strike Beacon, SystemBC, and Brute Ratel C4 backdoors, and notably, often utilizes command-and-control (C2) infrastructure established by Storm-0365, indicating close collaboration or shared resources. This actor is characterized by hands-on-keyboard activity, culminating in the deployment of Black Basta ransomware. A resurgence in activity observed in October 2024, directly linked to Storm-1674's vishing, underscores the ongoing and adaptive threat that Storm-0506 represents within the ransomware landscape.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Telecommunications
Manufacturing
Healthcare
Education
Energy
Transportation
Critical infrastructure
Media
Information technology
Retail
Aerospace
Hospitality
Mining
Pharmaceutical
Aviation
Non profit
Maritime
Chemical
Legal services
Nuclear
Gaming
Think tank

Targeted Countries / Regions

US
RU
UA
BR
KR
CN
GB
IN
PL
AU
MX
IL
ES
CA
JP
DE
TR
SY
TW
IT
SA
IR
FR
VN
SG
AE
NL
AZ
KZ
KP

AI Analysis

· 1 week ago

Executive Summary

Storm-0506 is a financially motivated cybercriminal group operating as a core affiliate within the Black Basta ransomware-as-a-service (RaaS) ecosystem. Originally deploying Conti ransomware, they transitioned to Black Basta in April 2022. They utilize a dynamic network of initial access brokers and exhibit hands-on-keyboard activity, making them a significant threat in the ransomware landscape.

Goals & Targeting

Storm-0506's primary motivation is financial gain through ransomware operations. They target sectors with high potential for payouts, including finance, healthcare, manufacturing, and critical infrastructure. Their targeting profile reflects a focus on organizations in regions where RaaS affiliates are active, leveraging initial access brokers to expand their reach.

Enhanced Description

Storm-0506 operates as a core affiliate within the Black Basta ransomware-as-a-service (RaaS) ecosystem. Initially deploying Conti ransomware, they transitioned to Black Basta in April 2022. Their operational model is characterized by strategic reliance on a network of initial access brokers, reflecting a division of labor common in RaaS operations. Storm-0506 has leveraged access obtained through various brokers: initially via Qakbot infections (pre-September 2023), then expanding to include Storm-1674 delivering DarkGate, Pikabot, and IcedID (September 2023), and later employing Storm-1674's Microsoft Teams vishing campaigns (October 2024) and Storm-0569's SEO poisoning leading to BATLOADER and Cobalt Strike (December 2023). Their post-exploitation toolkit includes Cobalt Strike Beacon, SystemBC, and Brute Ratel C4 backdoors. Notably, they often utilize command-and-control (C2) infrastructure established by Storm-0365, indicating close collaboration or shared resources. Following initial compromise, they deploy Black Basta ransomware directly. A resurgence in activity observed in October 2024, linked to Storm-1674's vishing campaigns, underscores their ongoing and adaptive threat within the ransomware landscape.

Key Capabilities

  • Leverages initial access brokers for compromising targets
  • Utilizes multiple ransomware families (Conti, Black Basta)
  • Employs Cobalt Strike Beacon and other post-exploitation tools
  • Deploys C2 infrastructure provided by Storm-0365
  • Engages in dynamic operational strategies including vishing and SEO poisoning

MITRE ATT&CK Tactics

Initial Access
Exfiltration
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Cobalt Strike Beacon
SystemBC
Brute Ratel C4
Qakbot

Campaigns & Victims

Storm-0506 has demonstrated a clear pattern of campaign activity, leveraging evolving methods such as vishing and SEO poisoning. Their use of multiple initial access brokers and affiliate networks highlights their adaptability and ability to scale operations quickly. Notable past operations include Conti ransomware campaigns before transitioning to Black Basta, as well as recent activity linked to Storm-1674's Microsoft Teams vishing campaigns in October 2024.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 infrastructure leveraging fast-flux domains associated with known CaaS providers
  • Use of Cobalt Strike Beacon for post-exploitation activities
  • Ransomware deployment indicative of Black Basta (encrypting files with .0506 extension)

Recommended Actions

  • Implement multi-factor authentication (MFA) for remote desktop protocols and critical systems.
  • Monitor for unusual network traffic and suspicious external communications, especially from known C2 domains.
  • Conduct regular employee training to mitigate phishing and vishing attempts.
  • Enhance email filtering to detect and block malicious attachments such as macro-laced Office documents.
  • Use endpoint detection and response (EDR) solutions to identify and block post-exploitation tools like Cobalt Strike Beacon.

Suggested Tags

ransomware
raas
financial-motivation
cybercrime
initial-access-broker

Confidence Assessment

High confidence in their role as a core affiliate within the Black Basta RaaS ecosystem, based on linked intelligence and observed campaign patterns. Some gaps exist regarding the full extent of their infrastructure and exact sources of initial access.

Observed Data

No observed data linked yet.

References

  1. www.microsoft.com — Cited by web research for: FIN7
  2. attack.mitre.org — Cited by web research for: Project Spy
  3. www.microsoft.com — Cited by web research for: Trickbot LLC
  4. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet
  5. learn.microsoft.com — Cited by web research for: Non Profit

Intel Summary

8

Techniques

40

Tools

1

Campaigns

40

IOCs

0

Observed Data

4

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
Backdoor / C2
ransomware
raas
financial-motivation
cybercrime
initial-access-broker

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.