Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors STAC5143

Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Sangria Tempest, Carbon Spider, obfuscation methods, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

STAC5143 operates predominantly through Microsoft Office 365 legitimate services, exploiting the platform’s cloud infrastructure to facilitate both initial compromise and subsequent lateral movement. The actor typically begins with mass‑email campaigns that overwhelm victim email servers (Email Bombing), followed by social engineering leveraging Microsoft Teams or Quick Assist to convince users of legitimate support sessions. Once remote access is achieved, STAC5143 downloads Java Archive files and Python‑based backdoors from SharePoint endpoints, installing ransomware such as Black Basta and establishing persistence via custom payloads integrated into cloud machine images, containers, and Windows service binaries. Their tactics exhibit advanced obfuscation: they mutate code, spoof HTTP headers and system identifiers to blend traffic with legitimate network flows, and exploit legitimate web services (e.g., OneDrive, S3 buckets) for command‑and‑control or exfiltration of stolen data. STAC5143 also proactively creates new local or domain accounts using tools like `net user`, enabling continued access even after remediation efforts. The group demonstrates the capability to hijack Windows service binaries by abusing file permissions and to embed malicious images within container registries, thereby maintaining persistence across multiple layers. STAC5143’s operations have been observed to target smaller enterprises lacking robust security controls, exploiting MFA interception attempts and using DoS‑style traffic to pressure victims into ransom payments. Their use of cloud infrastructure for both attack delivery and data exfiltration underscores a strategy that blends insider‑like persistence with the agility afforded by SaaS platforms.

Goals & Targeting

Targeted Sectors

Media
Financial services
Defense
Government
Information technology

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

STAC5143 is a financially motivated threat actor that targets small to medium‑sized organizations across media, finance and defense sectors using sophisticated Microsoft Office 365 services for initial access and remote exploitation. Their operations combine large‑scale email bombing with social engineering via Teams/Quick Assist to gain remote control, after which they deploy ransomware and backdoors while establishing persistence in cloud images and local systems. The group abuses legitimate third‑party web services for command‑and‑control, data exfiltration, and account hijacking, leveraging polymorphic code and service hijacking to evade detection.

Goals & Targeting

STAC5143’s primary strategic objective appears to be revenue generation through ransomware and extortion, specifically targeting small‑to‑medium businesses that are perceived as having lower security maturity. The actor prioritizes sectors where financial transactions or critical data can be leveraged for higher ransom yields—media, finance, defense, government, and IT services. By leveraging Microsoft Office 365 services, STAC5143 reduces the need to maintain independent infrastructure while gaining access to a wide array of victim assets. Their targeting profile reflects an opportunistic stance: they focus on organizations with limited MFA usage or poorly audited remote‑assistance tooling, enabling social engineering and credential theft for broader persistent compromise.

Enhanced Description

Key Capabilities

  • Email Bombing initial access
  • Social engineering via Microsoft Teams/Quick Assist for remote session takeover
  • Download and deploy ransomware and backdoor malware
  • Persistence through installation of malicious payloads (including in cloud images and containers)
  • Reconnaissance & credential gathering (account discovery, service discovery, MFA interception)
  • Data exfiltration via web services or other channels (cloud storage buckets)
  • Account creation & management on email/cloud providers for infrastructure acquisition
  • Exploitation of remote‑service vulnerabilities for lateral movement
  • Hijack Windows service binaries via file‑permission abuse
  • Spoofing HTTP headers/system attributes to blend malicious traffic
  • Targeting multi‑factor authentication mechanisms for credential harvesting or bypass
  • Network denial‑of‑service attacks for disruption/extortion
  • Port scanning & vulnerability scanning to harvest service lists
  • Polymorphic/mutating code & obfuscation techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Command and Control
Collection
Exfiltration
Defense Evasion
Impact

ATT&CK Techniques

T1566.001
T1204.002
T1219
T1136.001
T1059.003
T1136
T1520
T1016.001
T1027
T1533
T1543.003
T1574.002
T1499
T1037
T1557
T1583
T1613
T1123
T1547
T1119
T1115
T1071
T1659
T1010
T1560
T1185
T1580
T1217
T1092
T1595
T1548
T1087
T1059
T1482
T1020
T1609
T1584
T1612
T1586
T1619
T1554
T1098
T1110
T1531
T1671
T1197
T1650
T1651
T1134
T1526
T1538
T1105

Software / Tooling

Microsoft Quick Assist
Microsoft Teams
MailSniper
PowerShell
Black Basta
netsh
Nltest
OneDrive
Msiexec
Windows Command Shell
GitHub
TeamViewer
curl
BITS
Rundll32
mshta
Web Shell
Rootkit
XenAllPasswordPro
DCSync
MSBuild

Campaigns & Victims

STAC5143 has executed several ransomware campaigns that commence with automated email bombing to flood networks, followed by phishing or social‑engineering vectors exploiting remote assistance software. Victims are predominantly small or mid‑market businesses lacking robust MFA or audit controls, which allows the actor to achieve initial footholds quickly and establish persistence via cloud images and Windows services. The group demonstrates a high operational tempo—rapid recon, account provisioning, and exfiltration bursts—often completing the full attack lifecycle within days. Historically, STAC5143 has leveraged legitimate Microsoft assets (Teams, SharePoint, OneDrive) for staging files and command delivery, reducing their footprint in external infrastructure while maintaining stealth through polymorphic payloads and permission abuses.

IOC Patterns

  • Mass email spam
  • Remote assistance session requests via Microsoft Teams
  • Local/domain account creation with `net user`
  • Abuse of third‑party web services for C2 or exfiltration
  • Suspicious bulk email/cloud accounts provisioning
  • Unusual uploads to cloud storage buckets (S3, Dropbox, OneDrive)
  • Modified Windows service binaries/permission changes
  • Malicious images in container registries or AMI repositories
  • Forged HTTP headers/user agents
  • MFA interception/bypass attempts
  • Network DoS traffic

Recommended Actions

  • Monitor outbound email volume per user to detect Email Bombing patterns
  • Restrict usage of remote assistance tools (Quick Assist, Teams screen sharing) to authorized personnel only
  • Enforce multi‑factor authentication for all accounts, particularly those used for remote support
  • Deploy endpoint detection and response solutions that flag suspicious downloads or installation of ransomware/backdoors
  • Implement strict monitoring of local/domain account creation events
  • Limit external exfiltration paths and inspect outbound traffic over web services (e.g., OneDrive, S3)
  • Detect attempts to intercept or bypass MFA via anomaly detection
  • Enforce strict file‑permission controls on Windows service binaries and directories
  • Deploy file integrity monitoring for critical system executables
  • Audit and restrict creation of cloud/email accounts; set alerts for bulk provisioning
  • Use container image signing, scanning, and registry access control to prevent malicious imagery
  • Employ traffic analysis/anomaly detection to identify spoofed user‑agent strings or forged headers
  • Detect & mitigate network DoS attempts through rate limiting, IDS/IPS signatures

Suggested Tags

STAC5143
ransomware
phishing
social engineering
remote exploitation
credential theft
email bombing
web service abuse
cloud persistence
service hijacking
polymorphic malware
DoS attack
email account abuse
MFA bypass
exfiltration to cloud storage

Sources

Confidence Assessment

The assessment is based on multiple intelligence briefings that consistently describe STAC5143’s tactics, techniques and procedures, providing a high confidence view of their operational capabilities. However, gaps remain regarding the precise attribution timeline, detailed infrastructure footprints (IP ranges, C2 domain), and full coverage of all campaigns across sectors. As new indicators surface, confidence in mapping specific TTPs to the actor will improve, but current insights provide actionable guidance for defenders.

ATT&CK Techniques

Exfiltration
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 15 Filename 3 IPv4 Address 1 SHA-256 Hash 1

References

  1. attack.mitre.org — Cited by web research for: services
  2. mallory.ai — Cited by web research for: Sangria Tempest
  3. attack.mitre.org — Cited by web research for: PowerShell
  4. www.esentire.com — Cited by web research for: Payload
  5. www.sophos.com — Cited by web research for: curl

Intel Summary

52

Techniques

44

Tools

0

Campaigns

58

IOCs

0

Observed Data

14

Tactics

Tags

Ransomware
Phishing
Backdoor / C2
APT
Data Extortion
Financial Fraud
STAC5143
ransomware
phishing
social engineering
remote exploitation
credential theft
email bombing
web service abuse
cloud persistence
service hijacking
polymorphic malware
DoS attack
email account abuse
MFA bypass
exfiltration to cloud storage

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.