Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0826

Also known as: QBot, QuackBot, Pinkslipbot, APT28, tracked as, Pawn Storm, Fancy Bear, Memory Integrity, Unit243, Sandworm, which is profiled below, Trickbot LLC, DEV-0230, FIN7, Sednit, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, Blue Echidna, FROZENBARENTS, UAC-0113, Seashell Blizzard, UAC-0082, APT44, SANDWORM RELIC

Description

Storm‑0826 is identified primarily through its participation in the Black Basta ransomware-as-a-service (RaaS) framework, where it acts as an affiliate distributing malware via handoffs from other distributors such as Storm‑0464. The group’s toolkit blends classic espionage techniques with aggressive financial motives; it deploys destructive wipers like CaddyWiper, SDelete and KillDisk to destroy data and disrupt operations, while also dropping ransomware payloads such as Prestige. Operationally, the actor relies on a mix of well‑known Microsoft Office exploits (CVE‑2014‑4114, CVE‑2013‑3906), server‑side vulnerabilities in HMI software (GE Cimplicity, Advantech/Broadwin) and public‑facing services like EXIM to acquire initial access. Once inside it establishes persistence through the creation of systemd units on Linux or Windows services, utilizes Group Policy Objects for mass deployment, and maintains command-and-control via PowerShell, Telegram Bot APIs, and occasionally custom backdoors in Dropbear SSH. Storm‑0826’s tactics also encompass thorough reconnaissance—enumerating email accounts with tools such as M.E.Doc, harvesting credentials from password stores, and compiling victim network information—followed by lateral movement enabled by the creation of privileged domain accounts and exploit of known credential acquisition vectors. The group is known to target both IT and OT environments, particularly exemplified by the 2022 Ukraine electric‑power grid attack in which it leveraged systemd persistence and exploited HMI vulnerabilities. Beyond infrastructure sabotage, its primary motive remains financial gain through ransom payouts, backup deletion, and market influence via the RaaS platform. Overall, Storm‑0826 represents a hybrid threat: financially driven yet capable of state‑grade sabotage; it blends destructive wipers with ransomware and sophisticated supply‑chain techniques to maximize impact.

Goals & Targeting

Targeted Sectors

Financial services
Manufacturing
Government
Defense
Energy
Healthcare
Media
Telecommunications
Critical infrastructure
Non profit
Transportation
Hospitality
Chemical
Information technology
Retail

Targeted Countries / Regions

UA
US
RU
IQ
IR
IL
SA
PL
GB

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 days ago

Executive Summary

Storm‑0826 is a financially motivated cybercriminal group that operates within the Black Basta ransomware-as-a-service ecosystem. The actor delivers destructive wipers and ransomware to a wide range of sectors—including finance, energy, healthcare, and critical infrastructure—using spearphishing, exploitation of public‑facing CVEs and persistent backdoors such as Dropbear SSH. Their campaigns leverage PowerShell scripts, rundll32 DLL execution, and systemd or Windows services for persistence while regularly deleting backups to increase ransom value.

Goals & Targeting

Storm‑0826’s strategic objectives are dual‑faced: first, to extract maximum monetary value through the deployment of ransomware (Prestige, Black Cat) and destructive wiper tools (CaddyWiper), and second, to further cement its presence in target sectors by demonstrating operational capability against critical infrastructure. By leveraging existing infrastructure via STORM‑0464 handoffs and exploiting public CVEs, the group reduces risk while expanding geographic reach—including the U.S., U.K., EU, Middle East, and Gulf states—thereby increasing the pool of potential ransom victims across finance, government, energy, healthcare, and telecommunications domains.

Enhanced Description

Key Capabilities

  • Use PowerShell scripts for command‑and‑control
  • Deploy VBA macros and malicious Office attachments
  • Persist via systemd services (Linux) and Windows service modification
  • Create privileged domain accounts for lateral movement
  • Conduct spearphishing using third‑party email management services
  • Exploit public‑facing vulnerabilities (EXIM, Microsoft Office CVEs)
  • Drop destructive wiper components (CaddyWiper, SDelete, KillDisk)
  • Maintain persistence via Dropbear SSH backdoor
  • Distribute malware through GPO objects
  • Target OT infrastructure and exploit HMI software vulnerabilities
  • Establish internal proxies before deploying persistence mechanisms
  • Use Telegram Bot API for C2 communications
  • Create scheduled tasks for persistence
  • Delete backups and shadow copies
  • Encrypt data with Base64, Triple DES, AES
  • Compress data using GZip or zlib

ATT&CK Techniques

Exfiltration
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Sandworm
  2. www.microsoft.com — Cited by web research for: which is profiled below
  3. attack.mitre.org — Cited by web research for: BlackCat

Intel Summary

40

Techniques

43

Tools

2

Campaigns

66

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Critical Infrastructure
ransomware
financial-motivation
affiliate-group

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.