Also known as: Vice Society, Storm-0900, EtterSilent, Storm-0494 by MSTIC, DEV-0832, CleanUpLoader, Broomstick
Storm‑0494 operates as a modular threat organization that orchestrates complex, multi‑stage campaigns. Initial access is typically gained through macro‑enabled Excel phishing emails branded with impersonated logos, often routed via cloud hosting (Amazon S3) or Blogspot lures to obscure the final payload. Once in target systems, the actor deploys GootLoader – a versatile loader that drops secondary backdoors such as Tsundere Bot, Vanilla Tempest and OysterLoader, which further propagate ransomware payloads like INC Ransomware. The group is adept at exploiting both Windows and Linux vectors. On Windows, it leverages credential dumping via ntdsutil against NTDS.dit files and exploits the CVE‑2025‑55182 (React2Shell) vulnerability for remote code execution on Linux machines. Persistence is achieved through startup folder entries, scheduled tasks and registry modifications, while defense evasion routines include clearing event logs and deleting keys tied to terminal server connections. Operationally, Storm‑0494 targets a broad array of institutions including healthcare, finance, government, defense, manufacturing, critical infrastructure, non‑profits, think‑tanks, media and construction across multiple countries such as the US, Australia, Israel, Germany, UK, Russia, North Korea and India. The actor’s focus on financially rewarding sectors and reliance on supply‑chain and criminal services demonstrates an intent to maximize return while minimizing exposure. The campaign timeline remains unclear but evidence shows a pattern of rapid dissemination following public‑facing exploitation, followed by ransomware installation, data exfiltration via compressed ZIP archives and subsequent cleanup.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑0494, also known as Vice Society or Storm‑0900, is a financially driven threat actor that blends sophisticated phishing campaigns with multi‑stage delivery chains to infect high‑value sectors such as healthcare, finance and government. The group leverages GootLoader infections, macro‑enabled Excel attachments and third‑party hosting services to deliver backdoors and ransomware families like INC and Rhysida, while routinely exploiting unpatched public‑facing services and default credentials.
Goals & Targeting
The actor’s strategic objectives revolve around monetizing compromised environments through ransomware deployment and optional credential harvesting. By targeting sectors that are both financially critical and willing to pay for restoration or data protection (e.g., healthcare, finance), Storm‑0494 maximizes its leverage. Their geographic spread across Western and Eastern markets illustrates a global reach, while the use of social engineering and third‑party services indicates a low‑maintenance but high‑yield operational model.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑0494 follows a structured, multi‑stage operational pattern: initial compromise via macro phishing and GootLoader deployment, followed by lateral movement using RDP and WMI Provider Host. The actor frequently leverages third‑party criminal services and cloud hosting to obfuscate delivery paths and reduce detection risk. Victim organizations tend to be high‑profile entities capable of paying ransoms or providing valuable data. Recent campaigns have targeted the U.S. healthcare sector with INC Ransomware, while also expanding reach to Germany, Australia and India. The group’s operational tempo appears moderate – campaigns launch quickly once vulnerabilities are identified but rely on established backdoor loaders for persistence. Notable past operations include a U.S. media‑company breach employing GootLoader to drop Tsundere Bot, followed by deployment of Rhysida ransomware; and a European financial institution attack that leveraged the React2Shell vulnerability to infiltrate Linux assets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on corroborated intelligence from multiple sources, including industry reports and IOC feeds. While the core capabilities and campaign tactics are well‑documented, gaps remain regarding precise timing of operations, detailed infrastructure footprint, and full scope of affected sectors beyond the broad list provided. The actor’s sophistication level cannot be definitively classified due to limited information on internal development practices or code reuse.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics