Also known as: QBot, QuackBot, Pinkslipbot, APT28, tracked as, Pawn Storm, Fancy Bear, Memory Integrity, Unit243, Sandworm, which is profiled below, Trickbot LLC, DEV-0230, FIN7, Sednit, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, Blue Echidna, FROZENBARENTS, UAC-0113, Seashell Blizzard, UAC-0082, APT44, SANDWORM RELIC
Storm‑0826 is identified primarily through its participation in the Black Basta ransomware-as-a-service (RaaS) framework, where it acts as an affiliate distributing malware via handoffs from other distributors such as Storm‑0464. The group’s toolkit blends classic espionage techniques with aggressive financial motives; it deploys destructive wipers like CaddyWiper, SDelete and KillDisk to destroy data and disrupt operations, while also dropping ransomware payloads such as Prestige. Operationally, the actor relies on a mix of well‑known Microsoft Office exploits (CVE‑2014‑4114, CVE‑2013‑3906), server‑side vulnerabilities in HMI software (GE Cimplicity, Advantech/Broadwin) and public‑facing services like EXIM to acquire initial access. Once inside it establishes persistence through the creation of systemd units on Linux or Windows services, utilizes Group Policy Objects for mass deployment, and maintains command-and-control via PowerShell, Telegram Bot APIs, and occasionally custom backdoors in Dropbear SSH. Storm‑0826’s tactics also encompass thorough reconnaissance—enumerating email accounts with tools such as M.E.Doc, harvesting credentials from password stores, and compiling victim network information—followed by lateral movement enabled by the creation of privileged domain accounts and exploit of known credential acquisition vectors. The group is known to target both IT and OT environments, particularly exemplified by the 2022 Ukraine electric‑power grid attack in which it leveraged systemd persistence and exploited HMI vulnerabilities. Beyond infrastructure sabotage, its primary motive remains financial gain through ransom payouts, backup deletion, and market influence via the RaaS platform. Overall, Storm‑0826 represents a hybrid threat: financially driven yet capable of state‑grade sabotage; it blends destructive wipers with ransomware and sophisticated supply‑chain techniques to maximize impact.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑0826 is a financially motivated cybercriminal group that operates within the Black Basta ransomware-as-a-service ecosystem. The actor delivers destructive wipers and ransomware to a wide range of sectors—including finance, energy, healthcare, and critical infrastructure—using spearphishing, exploitation of public‑facing CVEs and persistent backdoors such as Dropbear SSH. Their campaigns leverage PowerShell scripts, rundll32 DLL execution, and systemd or Windows services for persistence while regularly deleting backups to increase ransom value.
Goals & Targeting
Storm‑0826’s strategic objectives are dual‑faced: first, to extract maximum monetary value through the deployment of ransomware (Prestige, Black Cat) and destructive wiper tools (CaddyWiper), and second, to further cement its presence in target sectors by demonstrating operational capability against critical infrastructure. By leveraging existing infrastructure via STORM‑0464 handoffs and exploiting public CVEs, the group reduces risk while expanding geographic reach—including the U.S., U.K., EU, Middle East, and Gulf states—thereby increasing the pool of potential ransom victims across finance, government, energy, healthcare, and telecommunications domains.
Enhanced Description
Key Capabilities
Australian Parliament Hack
Citrix Hack
No observed data linked yet.
40
Techniques
43
Tools
2
Campaigns
66
IOCs
0
Observed Data
13
Tactics