Also known as: STATIC TUNDRA, Sandworm Team, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, ION-87 by Insikt Group, APT28, Fancy Bear, Strontium, Forest Blizzard, APT44, Sandworm, Iridium
Storm‑1679 is likely an amalgamation of multiple Russian–and‑Iranian state‑aligned groups that have executed both cyber sabotage and disinformation campaigns against diverse targets worldwide. The actor’s repertoire encompasses the exploitation of well‑known public‑facing vulnerabilities—most notably SharePoint CVE‑2019-0604—and newly discovered zero‑days such as CVE‑2024-39717 on Versa Director servers to gain initial footholds in managed service provider (MSP) and ISP infrastructures. Once inside, they deploy a suite of destructive wiper families—including DynoWiper, LazyWiper, CaddyWiper, and KillDisk—capable of wiping critical infrastructure data sets and crippling operations. Alongside technical disruption, Storm‑1679 has demonstrated sophisticated cyber‑warfare against industrial control systems (ICS/SCADA), remotely issuing unauthorized commands to physical assets. Their toolset also incorporates PowerShell‑based living‑off‑the‐network scripts and legacy backdoors such as PlugX, Industroyer, and VPNFilter firmware exploits. In addition, the actor conducts targeted information operations during high‑profile events, notably the 2024 Olympic Games. Using AI‑generated deepfakes, fabricated narratives, and misattributed media outlets, Storm‑1679 has amplified anti‑Olympic sentiment, falsely attributing activity to North Korean or Chinese adversaries. These influence tactics are coupled with “False‑flag” operations that aim to obfuscate the true source of attacks. Overall, Storm‑1679 blends disruptive technical capabilities with strategic manipulation, making it a versatile threat to both critical infrastructure and public perception infrastructures.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑1679 appears to be an umbrella label for several related threat actors, including Sandworm/Iranian elements such as VOID MANTICORE and Razing Ursa. They combine destructive wiper operations, zero‑day and public‑facing application exploitation, and industrial control system attacks with high‑profile influence campaigns targeting the Olympic Games. Their operational patterns suggest a blend of financially motivated intrusions and state‑sponsored information warfare.
Goals & Targeting
Storm‑1679’s strategic objectives appear dual: secure long‑term financial gain through destructive wiper campaigns against high‑budget sectors; and deliver state‑oriented influence by shaping narratives around globally visible events such as the Olympic Games. Their targeting profile spans every sector—government, energy, transportation, healthcare, finance, media, and critical infrastructure—reflecting an intent to maximize both monetary payloads and geopolitical leverage.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑1679 is known to operate on a regular, often opportunistic cadence, exploiting widely publicized vulnerabilities for initial access and deploying destructive wiper payloads against high-value infrastructure. The actor’s campaigns target critical sectors globally—including government entities in the U.S., EU, Middle East, and Asia-Pacific—while periodically executing synchronized influence operations during event‑centered opportunities such as the Winter Olympics. Past incidents involve coordinated attacks on broadcasting networks, SCADA systems in Ukraine, and multiple disinformation sites purporting to mimic official media. The use of false‑flag tactics complicates attribution, with claims sometimes directed at adversaries like North Korea or China.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available information indicates a moderate confidence level in the technical capabilities—e.g., wiper usage and exploitation of specific CVEs—supported by multiple independent reports. However, the conflation of many aliases under Storm‑1679 introduces attribution uncertainty, particularly regarding the disinformation aspect and financial motives. Data gaps remain concerning precise timelines, victim counts, and confirmation that all listed tactics are employed together in a single campaign.
Australian Parliament Hack
Citrix Hack
No observed data linked yet.
44
Techniques
58
Tools
2
Campaigns
38
IOCs
0
Observed Data
14
Tactics