Also known as: DEV-0249, tracked as, response solutions, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Agenda Ransomware
Storm-0249 has evolved from broad mass phishing operations into focused, high‑value attacks that leverage trusted business processes. Recent observations show the actor employing tax‑themed email campaigns that bundle malicious PDFs intended to inject or download BRc4 and Latrodectus tools. The PDFs often exploit known vulnerabilities in Microsoft Office or rely on embedded scripts for execution. The group functions as an access broker, not only delivering malware directly but also enabling other threat actors—such as Storm-0501—to gain footholds by providing compromised credentials or vulnerable entry points. This collaboration model expands the reach of their operations across multiple geopolitical contexts. Storm-0249’s technical repertoire includes DLL injection, process discovery, system information gathering, and obfuscated binaries that hinder detection. They also practice local data staging for exfiltration and employ tactics to disable or modify security tools. Their catalog of malware—BazaLoader, IcedID, Bumblebee, Emotet, BRc4, Latrodectus—spans banking trojans, credential stealers, and utility kits tailored for persistence and lateral movement. The actor’s campaigns demonstrate a capacity to operate at scale, having sent thousands of spear‑phishing messages in a single month. They maintain a global foothold, targeting sectors ranging from finance and healthcare to defense and critical infrastructure, reflecting both opportunistic economic motives and a willingness to adapt tactics across diverse environments.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm-0249 is an access broker that has operated since 2021, selling and distributing malware such as BazaLoader, IcedID, Bumblebee, Emotet, BRc4, and Latrodectus. The group primarily delivers payloads through precision spear‑phishing campaigns—most recently using tax‑themed PDF attachments—to victims in a wide range of sectors worldwide. Their primary motivation is financial gain, achieved by monetizing stolen credentials and facilitating initial access for other threat actors.
Goals & Targeting
Storm-0249’s strategic objectives focus on generating revenue through the sale of malware, credential theft, and providing initial access for other threat actors. The group selects targets based on perceived monetary value—often engaging financial services, government agencies, and critical infrastructure—to maximize potential payouts or leverage stolen data for further exploitation. Their global list of targeted countries (including the US, RU, CN, IR, IL, UA, DE, UK, BR) indicates a pursuit of high‑profile victims while avoiding jurisdictions with stringent law enforcement cooperation. Typical victims are organizations that manage sensitive financial or personal information and have public-facing services that can be exploited for infection vector delivery.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-0249’s historical patterns illustrate a shift from noisy, mass phishing to precise, value‑driven campaigns that exploit trusted processes. The February 2025 Microsoft campaign involved thousands of tax-themed emails containing malicious PDFs designed to deliver red‑team tooling—an approach repurposed for ransomware and credential‑thealer rollouts. The actor frequently provides compromised credentials or vulnerable server access points for other threat actors, expanding its influence across unrelated campaigns. Operating at a high volume, Storm-0249 shows resilience in adapting its delivery mechanisms as defensive posture intensifies, suggesting a long‑term presence and active evolution.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence is derived primarily from a Microsoft security report dated February 2025 and commentary on December 9, 2025 that describe Storm‑0249’s shift to precision phishing. These sources provide firm evidence of malware distribution (BazaLoader, IcedID, Bumblebee, Emotet) and the use of tax‑themed PDF attachments for initial access. Confusion exists around the actor’s numerous aliases and potential overlap with groups such as APT28 or Sandworm Team; however, the focused operational patterns and tool catalog are consistently reported across sources. Gaps remain regarding the current activity level beyond 2025, detailed attribution of each campaign phase, and precise financial outcomes for the group
No campaigns linked yet.
No observed data linked yet.
9
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics