Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Sangria Tempest, Carbon Spider, obfuscation methods, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
STAC5143 operates predominantly through Microsoft Office 365 legitimate services, exploiting the platform’s cloud infrastructure to facilitate both initial compromise and subsequent lateral movement. The actor typically begins with mass‑email campaigns that overwhelm victim email servers (Email Bombing), followed by social engineering leveraging Microsoft Teams or Quick Assist to convince users of legitimate support sessions. Once remote access is achieved, STAC5143 downloads Java Archive files and Python‑based backdoors from SharePoint endpoints, installing ransomware such as Black Basta and establishing persistence via custom payloads integrated into cloud machine images, containers, and Windows service binaries. Their tactics exhibit advanced obfuscation: they mutate code, spoof HTTP headers and system identifiers to blend traffic with legitimate network flows, and exploit legitimate web services (e.g., OneDrive, S3 buckets) for command‑and‑control or exfiltration of stolen data. STAC5143 also proactively creates new local or domain accounts using tools like `net user`, enabling continued access even after remediation efforts. The group demonstrates the capability to hijack Windows service binaries by abusing file permissions and to embed malicious images within container registries, thereby maintaining persistence across multiple layers. STAC5143’s operations have been observed to target smaller enterprises lacking robust security controls, exploiting MFA interception attempts and using DoS‑style traffic to pressure victims into ransom payments. Their use of cloud infrastructure for both attack delivery and data exfiltration underscores a strategy that blends insider‑like persistence with the agility afforded by SaaS platforms.
Targeted Sectors
Executive Summary
STAC5143 is a financially motivated threat actor that targets small to medium‑sized organizations across media, finance and defense sectors using sophisticated Microsoft Office 365 services for initial access and remote exploitation. Their operations combine large‑scale email bombing with social engineering via Teams/Quick Assist to gain remote control, after which they deploy ransomware and backdoors while establishing persistence in cloud images and local systems. The group abuses legitimate third‑party web services for command‑and‑control, data exfiltration, and account hijacking, leveraging polymorphic code and service hijacking to evade detection.
Goals & Targeting
STAC5143’s primary strategic objective appears to be revenue generation through ransomware and extortion, specifically targeting small‑to‑medium businesses that are perceived as having lower security maturity. The actor prioritizes sectors where financial transactions or critical data can be leveraged for higher ransom yields—media, finance, defense, government, and IT services. By leveraging Microsoft Office 365 services, STAC5143 reduces the need to maintain independent infrastructure while gaining access to a wide array of victim assets. Their targeting profile reflects an opportunistic stance: they focus on organizations with limited MFA usage or poorly audited remote‑assistance tooling, enabling social engineering and credential theft for broader persistent compromise.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
STAC5143 has executed several ransomware campaigns that commence with automated email bombing to flood networks, followed by phishing or social‑engineering vectors exploiting remote assistance software. Victims are predominantly small or mid‑market businesses lacking robust MFA or audit controls, which allows the actor to achieve initial footholds quickly and establish persistence via cloud images and Windows services. The group demonstrates a high operational tempo—rapid recon, account provisioning, and exfiltration bursts—often completing the full attack lifecycle within days. Historically, STAC5143 has leveraged legitimate Microsoft assets (Teams, SharePoint, OneDrive) for staging files and command delivery, reducing their footprint in external infrastructure while maintaining stealth through polymorphic payloads and permission abuses.
IOC Patterns
Recommended Actions
Suggested Tags
Sources
Confidence Assessment
The assessment is based on multiple intelligence briefings that consistently describe STAC5143’s tactics, techniques and procedures, providing a high confidence view of their operational capabilities. However, gaps remain regarding the precise attribution timeline, detailed infrastructure footprints (IP ranges, C2 domain), and full coverage of all campaigns across sectors. As new indicators surface, confidence in mapping specific TTPs to the actor will improve, but current insights provide actionable guidance for defenders.
No campaigns linked yet.
No observed data linked yet.
52
Techniques
44
Tools
0
Campaigns
58
IOCs
0
Observed Data
14
Tactics