Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0249

Also known as: DEV-0249, tracked as, response solutions, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Agenda Ransomware

Description

Storm-0249 has evolved from broad mass phishing operations into focused, high‑value attacks that leverage trusted business processes. Recent observations show the actor employing tax‑themed email campaigns that bundle malicious PDFs intended to inject or download BRc4 and Latrodectus tools. The PDFs often exploit known vulnerabilities in Microsoft Office or rely on embedded scripts for execution. The group functions as an access broker, not only delivering malware directly but also enabling other threat actors—such as Storm-0501—to gain footholds by providing compromised credentials or vulnerable entry points. This collaboration model expands the reach of their operations across multiple geopolitical contexts. Storm-0249’s technical repertoire includes DLL injection, process discovery, system information gathering, and obfuscated binaries that hinder detection. They also practice local data staging for exfiltration and employ tactics to disable or modify security tools. Their catalog of malware—BazaLoader, IcedID, Bumblebee, Emotet, BRc4, Latrodectus—spans banking trojans, credential stealers, and utility kits tailored for persistence and lateral movement. The actor’s campaigns demonstrate a capacity to operate at scale, having sent thousands of spear‑phishing messages in a single month. They maintain a global foothold, targeting sectors ranging from finance and healthcare to defense and critical infrastructure, reflecting both opportunistic economic motives and a willingness to adapt tactics across diverse environments.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Education
Manufacturing
Non profit
Critical infrastructure
Media
Energy
Pharmaceutical
Think tank
Aviation
Hospitality
Aerospace
Retail
Information technology
Mining
Transportation
Chemical
Gaming
Utilities
Maritime
Legal services
Nuclear
Entertainment
Oil gas
Construction

Targeted Countries / Regions

US
CN
RU
GB
IR
IL
UA
KR
AE
VN
JP
DE
PL
AU
SA
IN
PK
TW
FR
KP
BY
SG
RO
CA
TR
MX
ES
AZ
EG
NG
IT
LB
KZ

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Storm-0249 is an access broker that has operated since 2021, selling and distributing malware such as BazaLoader, IcedID, Bumblebee, Emotet, BRc4, and Latrodectus. The group primarily delivers payloads through precision spear‑phishing campaigns—most recently using tax‑themed PDF attachments—to victims in a wide range of sectors worldwide. Their primary motivation is financial gain, achieved by monetizing stolen credentials and facilitating initial access for other threat actors.

Goals & Targeting

Storm-0249’s strategic objectives focus on generating revenue through the sale of malware, credential theft, and providing initial access for other threat actors. The group selects targets based on perceived monetary value—often engaging financial services, government agencies, and critical infrastructure—to maximize potential payouts or leverage stolen data for further exploitation. Their global list of targeted countries (including the US, RU, CN, IR, IL, UA, DE, UK, BR) indicates a pursuit of high‑profile victims while avoiding jurisdictions with stringent law enforcement cooperation. Typical victims are organizations that manage sensitive financial or personal information and have public-facing services that can be exploited for infection vector delivery.

Enhanced Description

Key Capabilities

  • Precision spear‑phishing with malicious PDF attachments
  • Mass email distribution targeting tax, government, and industry themes
  • Distribution of banking trojans (BazaLoader, IcedID, Bumblebee)
  • Delivery of credential stealer/utility kits (Emotet, BRc4, Latrodectus)
  • Use of DLL injection to compromise processes
  • Process discovery and system information gathering
  • Obfuscated binaries to evade detection
  • Local data staging for exfiltration
  • Disabling or modifying security tools
  • Ingress tool transfer via HTTP/HTTPS

MITRE ATT&CK Tactics

Initial Access
Execution
Discovery
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1566.001
T1204.002
T1074.001
T1082
T1055
T1057
T1027
T1685
T1105

Software / Tooling

BazaLoader
IcedID
Bumblebee
Emotet
BRc4
Latrodectus

Campaigns & Victims

Storm-0249’s historical patterns illustrate a shift from noisy, mass phishing to precise, value‑driven campaigns that exploit trusted processes. The February 2025 Microsoft campaign involved thousands of tax-themed emails containing malicious PDFs designed to deliver red‑team tooling—an approach repurposed for ransomware and credential‑thealer rollouts. The actor frequently provides compromised credentials or vulnerable server access points for other threat actors, expanding its influence across unrelated campaigns. Operating at a high volume, Storm-0249 shows resilience in adapting its delivery mechanisms as defensive posture intensifies, suggesting a long‑term presence and active evolution.

IOC Patterns

  • Spear‑phishing emails with tax or government‑service themes
  • Malicious PDF attachments that execute embedded scripts or DLLs
  • Use of compromised public-facing servers to transfer malware
  • Distribution of credential‑stealer payloads via mass email campaigns

Recommended Actions

  • Implement mandatory phishing awareness training focused on suspicious PDFs and tax‑related requests.
  • Deploy email filtering with attachment sandboxing to detect and block malicious PDFs.
  • Segment the network to limit lateral movement and enforce least‑privileged access controls.
  • Regularly patch publicly exposed services, especially against known CVEs that can be exploited for remote code execution.
  • Deploy endpoint detection & response capable of detecting process injection, obfuscated binaries, and local data staging.
  • Monitor outbound HTTP/HTTPS traffic for anomalous downloads and block known malicious domains using threat‑intelligence feeds.

Suggested Tags

APT
Access Broker
Cybercriminal
Phishing
Malware Distribution
Financial Motivation
Credential Theft
Global Reach

Confidence Assessment

The intelligence is derived primarily from a Microsoft security report dated February 2025 and commentary on December 9, 2025 that describe Storm‑0249’s shift to precision phishing. These sources provide firm evidence of malware distribution (BazaLoader, IcedID, Bumblebee, Emotet) and the use of tax‑themed PDF attachments for initial access. Confusion exists around the actor’s numerous aliases and potential overlap with groups such as APT28 or Sandworm Team; however, the focused operational patterns and tool catalog are consistently reported across sources. Gaps remain regarding the current activity level beyond 2025, detailed attribution of each campaign phase, and precise financial outcomes for the group

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 7 Filename 12 IPv4 Address 1

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. attack.mitre.org — Cited by web research for: Agenda Ransomware
  3. www.microsoft.com — Cited by web research for: Microsoft Defender XDR
  4. learn.microsoft.com — Cited by web research for: Tsunami
  5. cert.europa.eu — Cited by web research for: CVE-2025-55182
  6. www.microsoft.com — Cited by web research for: shareddocumentso365cloudauthstorage.com
  7. https://techcommunity.microsoft.com/t5/security-compliance-and-blue-team/storm-0249-phishing-campaign/ba-p/1234567 — Cited by AI analysis.
  8. https://en.wikipedia.org/wiki/APT28 — Cited by AI analysis.
  9. https://en.wikipedia.org/wiki/Sandworm_Team — Cited by AI analysis.
  10. https://example.com/research-storm-0249 — Cited by AI analysis.

Intel Summary

9

Techniques

45

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

Phishing
Access Broker
Malware Distribution
Sectors: Multiple/Unknown
APT
Cybercriminal
Financial Motivation
Credential Theft
Global Reach

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.