Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0494

Also known as: Vice Society, Storm-0900, EtterSilent, Storm-0494 by MSTIC, DEV-0832, CleanUpLoader, Broomstick

Description

Storm‑0494 operates as a modular threat organization that orchestrates complex, multi‑stage campaigns. Initial access is typically gained through macro‑enabled Excel phishing emails branded with impersonated logos, often routed via cloud hosting (Amazon S3) or Blogspot lures to obscure the final payload. Once in target systems, the actor deploys GootLoader – a versatile loader that drops secondary backdoors such as Tsundere Bot, Vanilla Tempest and OysterLoader, which further propagate ransomware payloads like INC Ransomware. The group is adept at exploiting both Windows and Linux vectors. On Windows, it leverages credential dumping via ntdsutil against NTDS.dit files and exploits the CVE‑2025‑55182 (React2Shell) vulnerability for remote code execution on Linux machines. Persistence is achieved through startup folder entries, scheduled tasks and registry modifications, while defense evasion routines include clearing event logs and deleting keys tied to terminal server connections. Operationally, Storm‑0494 targets a broad array of institutions including healthcare, finance, government, defense, manufacturing, critical infrastructure, non‑profits, think‑tanks, media and construction across multiple countries such as the US, Australia, Israel, Germany, UK, Russia, North Korea and India. The actor’s focus on financially rewarding sectors and reliance on supply‑chain and criminal services demonstrates an intent to maximize return while minimizing exposure. The campaign timeline remains unclear but evidence shows a pattern of rapid dissemination following public‑facing exploitation, followed by ransomware installation, data exfiltration via compressed ZIP archives and subsequent cleanup.

Goals & Targeting

Targeted Sectors

Healthcare
Financial services
Non profit
Government
Defense
Manufacturing
Critical infrastructure
Think tank
Media
Construction

Targeted Countries / Regions

US
AU
IL
DE
GB
RU
KP
IN

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 21 hours ago

Executive Summary

Storm‑0494, also known as Vice Society or Storm‑0900, is a financially driven threat actor that blends sophisticated phishing campaigns with multi‑stage delivery chains to infect high‑value sectors such as healthcare, finance and government. The group leverages GootLoader infections, macro‑enabled Excel attachments and third‑party hosting services to deliver backdoors and ransomware families like INC and Rhysida, while routinely exploiting unpatched public‑facing services and default credentials.

Goals & Targeting

The actor’s strategic objectives revolve around monetizing compromised environments through ransomware deployment and optional credential harvesting. By targeting sectors that are both financially critical and willing to pay for restoration or data protection (e.g., healthcare, finance), Storm‑0494 maximizes its leverage. Their geographic spread across Western and Eastern markets illustrates a global reach, while the use of social engineering and third‑party services indicates a low‑maintenance but high‑yield operational model.

Enhanced Description

Key Capabilities

  • Initial Access via macro-enabled Excel phishing attachments
  • Social engineering with brand impersonation and email spoofing
  • Multi‑stage delivery using redirect chains, third‑party criminal services, Amazon S3 cloud hosting
  • Provision of initial access through GootLoader infections
  • Exploitation of unpatched public‑facing services and default privileged credentials
  • Credential dumping via ntdsutil on NTDS.dit files
  • Persistence through startup folder entries, scheduled tasks, registry modifications
  • Defense evasion by clearing event logs and deleting registry keys
  • Data exfiltration via compressed ZIP archives
  • Deployment of backdoor loaders such as Tsundere Bot, Vanilla Tempest, OysterLoader (CleanUpLoader/Broomstick)
  • Exploitation of CVE-2025‑55182 (React2Shell) to deliver Linux backdoors

MITRE ATT&CK Tactics

Credential Access
Defense Evasion
Execution
Initial Access
Persistence
Exfiltration

ATT&CK Techniques

T1003.003
T1027
T1059.007
T1053.005
T1102
T1112
T1222.001
T1547.001
T1566.001
T1629
T1190
T1070.001

Software / Tooling

EtterSilent (macro‑enabled Excel)
GootLoader
INC Ransomware
OysterLoader / CleanUpLoader / Broomstick
React2Shell
Tsundere Bot
Vanilla Tempest (DEV-0832)
XWorm

Campaigns & Victims

Storm‑0494 follows a structured, multi‑stage operational pattern: initial compromise via macro phishing and GootLoader deployment, followed by lateral movement using RDP and WMI Provider Host. The actor frequently leverages third‑party criminal services and cloud hosting to obfuscate delivery paths and reduce detection risk. Victim organizations tend to be high‑profile entities capable of paying ransoms or providing valuable data. Recent campaigns have targeted the U.S. healthcare sector with INC Ransomware, while also expanding reach to Germany, Australia and India. The group’s operational tempo appears moderate – campaigns launch quickly once vulnerabilities are identified but rely on established backdoor loaders for persistence. Notable past operations include a U.S. media‑company breach employing GootLoader to drop Tsundere Bot, followed by deployment of Rhysida ransomware; and a European financial institution attack that leveraged the React2Shell vulnerability to infiltrate Linux assets.

IOC Patterns

  • domain
  • file
  • ip-v4
  • url
  • hash-sha256
  • redirect chains to obscure final payload
  • third‑party criminal services in delivery
  • Amazon S3 URLs for hosting payloads
  • Blogspot domains used as lures
  • ZIP archive exfiltration patterns
  • clearing Windows event logs
  • deleting registry keys (terminal server client connections)

Recommended Actions

  • Implement email security controls and policy enforcement to detect/block macro‑enabled phishing attachments
  • Enable macro protection or disable macros in Microsoft Office apps across the enterprise
  • Apply timely patches for public‑facing services and remove default privileged accounts
  • Deploy URL reputation filtering, with special attention to AWS S3, Blogspot and other known malicious domains
  • Sandbox or analyze suspicious landing pages behind redirects
  • Enforce DMARC/SPF/DKIM anti‑spoofing controls to mitigate brand impersonation attempts
  • Monitor for startup folder entries, scheduled tasks and registry changes indicative of persistence
  • Block known backdoor loaders (Tsundere Bot, Vanilla Tempest, OysterLoader) through signature or behavioral detection
  • Restrict privileged access to NTDS files; enforce least‑privilege principles to prevent credential dumping

Suggested Tags

ThreatActor
FinancialMalignancy
Phishing
MacroBasedMalware
HealthcareSectorTarget
PublicFacingServicesExploitation
InitialAccessBroker
CloudHostingDelivery
MaaS
Backdoor
RansomwareDelivery
CredentialDumping
DefenseEvasion
JavaScriptLoader
GootloaderOperator

Confidence Assessment

The analysis is based on corroborated intelligence from multiple sources, including industry reports and IOC feeds. While the core capabilities and campaign tactics are well‑documented, gaps remain regarding precise timing of operations, detailed infrastructure footprint, and full scope of affected sectors beyond the broad list provided. The actor’s sophistication level cannot be definitively classified due to limited information on internal development practices or code reuse.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 5 URL 2 SHA-256 Hash 1 Filename 8 IPv4 Address 4

References

  1. www.proofpoint.com — Cited by web research for: Storm-0900
  2. www.huntress.com — Cited by web research for: Storm-0494 by MSTIC
  3. learn.microsoft.com — Cited by web research for: Tsunami
  4. www.bitdefender.com — Cited by web research for: LockBit
  5. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet
  6. https://www.bitsight.com/underground/threat-actors/inc-ransom — Cited by AI analysis.
  7. https://www.securityweek.com/microsoft-us-healthcare-sector-targeted-by-inc-rans — Cited by AI analysis.

Intel Summary

13

Techniques

45

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

Ransomware
Critical Infrastructure
Backdoor / C2
ThreatActor
FinancialMalignancy
Phishing
MacroBasedMalware
HealthcareSectorTarget
PublicFacingServicesExploitation
InitialAccessBroker
CloudHostingDelivery
MaaS
Backdoor
RansomwareDelivery
CredentialDumping
DefenseEvasion
JavaScriptLoader
GootloaderOperator

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.