Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1679

Also known as: STATIC TUNDRA, Sandworm Team, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, ION-87 by Insikt Group, APT28, Fancy Bear, Strontium, Forest Blizzard, APT44, Sandworm, Iridium

Description

Storm‑1679 is likely an amalgamation of multiple Russian–and‑Iranian state‑aligned groups that have executed both cyber sabotage and disinformation campaigns against diverse targets worldwide. The actor’s repertoire encompasses the exploitation of well‑known public‑facing vulnerabilities—most notably SharePoint CVE‑2019-0604—and newly discovered zero‑days such as CVE‑2024-39717 on Versa Director servers to gain initial footholds in managed service provider (MSP) and ISP infrastructures. Once inside, they deploy a suite of destructive wiper families—including DynoWiper, LazyWiper, CaddyWiper, and KillDisk—capable of wiping critical infrastructure data sets and crippling operations. Alongside technical disruption, Storm‑1679 has demonstrated sophisticated cyber‑warfare against industrial control systems (ICS/SCADA), remotely issuing unauthorized commands to physical assets. Their toolset also incorporates PowerShell‑based living‑off‑the‐network scripts and legacy backdoors such as PlugX, Industroyer, and VPNFilter firmware exploits. In addition, the actor conducts targeted information operations during high‑profile events, notably the 2024 Olympic Games. Using AI‑generated deepfakes, fabricated narratives, and misattributed media outlets, Storm‑1679 has amplified anti‑Olympic sentiment, falsely attributing activity to North Korean or Chinese adversaries. These influence tactics are coupled with “False‑flag” operations that aim to obfuscate the true source of attacks. Overall, Storm‑1679 blends disruptive technical capabilities with strategic manipulation, making it a versatile threat to both critical infrastructure and public perception infrastructures.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Media
Financial services
Energy
Transportation
Healthcare
Hospitality
Defense
Critical infrastructure
Aviation
Manufacturing
Information technology
Education
Maritime
Think tank
Non profit
Construction
Chemical
Aerospace
Legal services
Retail
Oil gas
Nuclear

Targeted Countries / Regions

US
IR
CN
RU
UA
IL
MX
IN
CA
JP
KR
GB
FR
AU
PL
SG
VN
TW
DE
IT
KZ
TR
BR
ES
KP
NG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Storm‑1679 appears to be an umbrella label for several related threat actors, including Sandworm/Iranian elements such as VOID MANTICORE and Razing Ursa. They combine destructive wiper operations, zero‑day and public‑facing application exploitation, and industrial control system attacks with high‑profile influence campaigns targeting the Olympic Games. Their operational patterns suggest a blend of financially motivated intrusions and state‑sponsored information warfare.

Goals & Targeting

Storm‑1679’s strategic objectives appear dual: secure long‑term financial gain through destructive wiper campaigns against high‑budget sectors; and deliver state‑oriented influence by shaping narratives around globally visible events such as the Olympic Games. Their targeting profile spans every sector—government, energy, transportation, healthcare, finance, media, and critical infrastructure—reflecting an intent to maximize both monetary payloads and geopolitical leverage.

Enhanced Description

Key Capabilities

  • Exploit public-facing application vulnerabilities (e.g., SharePoint CVE-2019-0604)
  • Deploy destructive wiper malware (DynoWiper, LazyWiper, CaddyWiper)
  • Exploitation of zero-day CVE-2024-39717 on Versa Director servers to harvest credentials
  • Use PowerShell-based living‑off‑the-network tools for operations
  • Credential theft and lateral movement via password spraying, brute force, dual-homed network exploitation
  • Remote control SCADA/ICS to issue unauthorized commands
  • Target broadcasters, officials, sponsors during the Winter Olympics with false‑flag attribution to North Korea/CN
  • Exploitation of device firmware using VPNFilter
  • Generate AI‑driven deepfakes and fabricated narratives for influence operations
  • Impersonate media outlets and create disinformation websites

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Discovery
Privilege Escalation
Defense Evasion
Persistence
Impact
Exfiltration
Resource Development

ATT&CK Techniques

T1003
T1005
T1027
T1036
T1041
T1046
T1071
T1071.001
T1074
T1087
T1098
T1110
T1110.001
T1110.002
T1114
T1123
T1133
T1134
T1190
T1485
T1486
T1489
T1490
T1560
T1561
T1564
T1570
T1583
T1585
T1587
T1588
T1589
T1595
T1651
T1657
T1679
T1685
T1686

Software / Tooling

BlackEnergy3
KillDisk
Industroyer
GOGETTER
Neo-REGEORG
CaddyWiper
DynoWiper
LazyWiper
VersaMem
Quad7
Sunburst
Olympic Destroyer
VPNFilter
Pikabot
BRICKSTORM
Matryoshka
J-magic
PlugX
ZeroCleare
Milan
FunnyDream
ROADSWEEP
Impacket
phishing
Turla
Triton
Winnti
Cobalt
China Chopper
Ckife Webshells
LazyCat
reGeorge
PowerShell
Dark
Nexus
Rogue
Conti
Tsunami
inter
Leverage
OilRig
Unknown
FrostyGoop
Global
Handala
Karma
Void
Backdoors
Group Policy
Windows Command Shell
Telegram
SolarWinds
Labyrinth Chollima
Web Shell
YARA
Imperial Kitten
ToolShell

Campaigns & Victims

Storm‑1679 is known to operate on a regular, often opportunistic cadence, exploiting widely publicized vulnerabilities for initial access and deploying destructive wiper payloads against high-value infrastructure. The actor’s campaigns target critical sectors globally—including government entities in the U.S., EU, Middle East, and Asia-Pacific—while periodically executing synchronized influence operations during event‑centered opportunities such as the Winter Olympics. Past incidents involve coordinated attacks on broadcasting networks, SCADA systems in Ukraine, and multiple disinformation sites purporting to mimic official media. The use of false‑flag tactics complicates attribution, with claims sometimes directed at adversaries like North Korea or China.

IOC Patterns

  • domain
  • file
  • CVE
  • TCP port

Recommended Actions

  • Patch all public-facing applications immediately (e.g., SharePoint) and monitor for exploitation attempts
  • Deploy EDR capable of detecting PowerShell scripts that launch wiper payloads
  • Block or restrict traffic on uncommon management ports such as TCP 7777 and 63256 used by known botnet infrastructure
  • Enforce multi‑factor authentication and network segmentation to mitigate credential spraying and brute‑force attempts
  • Implement signature or behavioral detection for DynoWiper, LazyWiper, CaddyWiper, and related wipers
  • Monitor SCADA/ICS traffic for anomalous commands originating from compromised devices
  • Setup threat hunting capabilities for Olympic Destroyer signatures on enterprise hosts
  • Keep firmware up‑to‑date to defend against VPNFilter exploitation
  • Validate the authenticity of information in high‑profile contexts to mitigate false‑flag campaigns
  • Secure broadcasting and event‑centric networks with hardened firewall rules and strict access controls

Suggested Tags

APT28
Sandworm Team
VOID MANTICORE
Wiper Malware
Public‑Facing Vulnerability Exploitation
Zero‑Day Exploitation
Credential Dumping
Botnet Activity
Industrial Control System Attack
APT44
Sandworm
Iridium
Razing Ursa
VPNFilter
Olympic Destroyer
False-Flag
Device Compromise
Winter Olympics
PyeongChang 2018
Disinformation
Deepfake
Information Operations

Confidence Assessment

The available information indicates a moderate confidence level in the technical capabilities—e.g., wiper usage and exploitation of specific CVEs—supported by multiple independent reports. However, the conflation of many aliases under Storm‑1679 introduces attribution uncertainty, particularly regarding the disinformation aspect and financial motives. Data gaps remain concerning precise timelines, victim counts, and confirmation that all listed tactics are employed together in a single campaign.

ATT&CK Techniques

Exfiltration
1 technique
Lateral Movement
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  2. www.recordedfuture.com — Cited by web research for: ION-87 by Insikt Group
  3. unit42.paloaltonetworks.com — Cited by web research for: APT28
  4. cloud.google.com — Cited by web research for: T1071.001
  5. attack.mitre.org — Cited by web research for: T1134
  6. learn.microsoft.com — Cited by web research for: Tsunami
  7. https://malpedia.caad.fkie.fraunhofer.de/details/win.sunburst — Cited by AI analysis.

Intel Summary

44

Techniques

58

Tools

2

Campaigns

38

IOCs

0

Observed Data

14

Tactics

Tags

Critical Infrastructure
APT
Disinformation
Political Influence
Social Engineering
Olympics
AI-Driven Threats
APT28
Sandworm Team
VOID MANTICORE
Wiper Malware
Public‑Facing Vulnerability Exploitation
Zero‑Day Exploitation
Credential Dumping
Botnet Activity
Industrial Control System Attack
APT44
Sandworm
Iridium
Razing Ursa
VPNFilter
Olympic Destroyer
False-Flag
Device Compromise
Winter Olympics
PyeongChang 2018
Deepfake
Information Operations

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.