Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1977

Also known as: tracked as

Description

Storm‑1977 is a multi‑stage attacker that conducts large‑scale password‑spraying campaigns against public cloud tenants (Azure and potentially other SaaS environments). The first vector used in most observed attacks is the AzureChecker.exe command‑line tool, which scans tenant directories for accessible files and then leverages misconfigured guest accounts to expand the attack surface by creating additional resource groups within compromised subscriptions. Once inside a subscription, the actor deploys cryptomining workloads into more than 200 containers across its victims. It uses the cloud native “Container CLI/API” (MITRE T1059.013) and PowerShell scripts to pull custom images and spin up mining pipelines while masking the activity behind legitimate infrastructure resources. The persistence layer relies heavily on container‑side tactics, such as modifying LSA authentication packages, abusing the Print Spooler DLL for persistence, and hijacking default file associations. To evade detection, Storm‑1977 abuses a broad set of credential theft techniques: Kerberoasting, golden/silver ticket forging (Kerberos tickets), and the use of application access tokens. It also manipulates firewall rules, injects code via copy‑paste operations, and uses BITS jobs or Office macros to deliver payloads. The actor’s operational footprint is distinguished by its ability to archive collected data through libraries and utilities while moving laterally through component object model (COM), dynamic data exchange (DDE), and XPC services.

Goals & Targeting

Targeted Sectors

Education
Financial services
Non profit
Defense
Mining
Energy
Government
Think tank
Media

Targeted Countries / Regions

IL
IT
RU
KP
IN

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Storm‑1977 is a financially motivated threat actor that targets cloud tenants, primarily in the education sector, using password‑spraying and the AzureChecker.exe CLI tool to compromise containers and deploy cryptocurrency mining operations. The group leverages guest account privileges to create new resource groups within compromised subscriptions, while employing sophisticated credential theft and persistence techniques to maintain footholds.

Goals & Targeting

The primary objective of Storm‑1977 appears to be the covert deployment of cryptocurrency mining operations across highly valuable cloud infrastructures. By compromising education, financial, non‑profit, defense, mining, energy, government, think‑tank and media tenants—especially in Israel, Italy, Russia, North Korea, and India—the group seeks high‑yield workloads that can generate significant passive income while maintaining a low attack surface through guest account exploitation.

Enhanced Description

Key Capabilities

  • Password spraying against cloud tenant accounts
  • Exploitation of AzureChecker.exe CLI tool for initial infection
  • Compromise of subscriptions via guest account to create new resource groups
  • Deployment of cryptocurrency mining in compromised containers
  • Archiving collected data using libraries or utilities
  • Forging Kerberos golden/silver tickets for persistence and lateral movement
  • Kerberoasting to harvest service principal names and credentials
  • LSA authentication package persistence via registry/LSASS DLL load
  • Browser session hijacking through privilege elevation and thread injection
  • Remote execution/persistence using Windows BITS jobs, Office macro templates, or default file association hijacks
  • Unauthorized modification of network firewall rules
  • Copy‑paste code injection attack vectors
  • Malicious file download/open chain leading to arbitrary payload deployment
  • Container image pull/run anomalies (privileged pulls into compromised environments)
  • Package manager misuse for installing malicious libraries
  • Persistence via Print Processor DLLs

MITRE ATT&CK Tactics

Collection
Credential Access
Privilege Escalation
Defense Evasion
Initial Access
Persistence
Command and Control
Lateral Movement
Impact
Execution

ATT&CK Techniques

T1560
T1560.001
T1560.002
T1560.003
T1558
T1558.001
T1558.002
T1558.003
T1558.004
T1558.005
T1548
T1134
T1134.001
T1134.002
T1134.003
T1134.004
T1134.005
T1559.001
T1559.002
T1559.003
T1550.001

Software / Tooling

SUNBURST
AzureChecker.exe

Campaigns & Victims

Storm‑1977 has been observed conducting repeated, high‑volume password‑spraying campaigns against Azure tenants since at least early 2023, achieving a breach rate within hundreds of accounts in targeted organizations. The actor systematically escalates privileges by leveraging guest account permissions to create new resource groups, which enables long‑term cryptomining while bypassing basic security controls that monitor only user accounts. Victims span diverse sectors—particularly education and finance—but the group also infiltrates government, defense and energy cloud environments, suggesting operational reach beyond a single industry focus. Operations show rapid deployment (within minutes of initial access) and high persistence scores due to the use of container‑level persistence primitives and LSA package abuse. Notable previous campaigns include an unnamed operation that compromised at least 200+ containers across multiple tenants in Israel and Russia, as well as a later incident targeting Italian finance services where the actor extracted extensive credentials through Kerberoasting before deploying mining workloads. The consistent pattern of guest‑account exploitation combined with advanced credential forging points to a coordinated infrastructure team rather than individual opportunists. Overall, the threat actor appears to operate at a fairly high tempo, maintaining multiple simultaneous infection vectors and focusing on cloud resource elasticity as a stealth mechanism for money generation.

IOC Patterns

  • Domain names associated with the actor (e.g., TEMP.Zagros, TEMP.Periscope, tcpdump101.com)
  • Executable files that indicate persistence or payload delivery (mavinject.exe, SyncAppvPublishingServer.vbs, PubPrn.vbs, sdbinst.exe, spoolsv.exe, InstallUtil.exe, control.exe, CMSTP.exe, hh.exe)
  • Suspicious system component names or usage patterns

Recommended Actions

  • Implement continuous monitoring for archive collection via libraries/utilities (T1560.*).
  • Deploy detection and alerting for forged Kerberos tickets (golden/silver) and Kerberoasting attempts.
  • Set up integrity checks and monitoring for LSA authentication package DLL loads to detect LSASS persistence.
  • Configure BITS jobs, Office macro templates, and default file association hijacking alerts with strict whitelist policies.
  • Enforce firewall rule change auditing and alert suspicious modifications initiated from within cloud environments.
  • Restrict and monitor copy‑paste operations in browsers and email clients to prevent injected code execution.
  • Apply rigorous scanning and sandboxing for any downloaded or opened files before execution, especially .exe and .vbs payloads.
  • Implement anomaly detection on container image pull/run activity, flagging privileged or unfamiliar image sources.
  • Audit package manager usage and block installation of unknown or malicious libraries.
  • Remove or quarantine Print Spooler DLl persistence modules found in compromised containers.

Suggested Tags

APT
Credential Access
Privilege Escalation
Defense Evasion
Persistence
Multiple Platforms
Firewall Modification
Malicious Copy‑Paste
Download/Open Execution
Container Image Attack
Package Manager Misuse
Print Spooler Persistence
SUNBURST
Cryptomining
Cloud-based Attacks
Password Spraying

Confidence Assessment

Moderate to high confidence in the documented TTPs – the behaviors have been observed across multiple reports and in diverse environments. However, gaps remain regarding the exact timeline of the actor’s first appearance, precise financial outcomes, and potential operations beyond cloud containers. Further evidence would solidify the attacker’s full scope and long‑term objectives.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: T1518.002
  2. learn.microsoft.com — Cited by web research for: Tsunami
  3. https://malpedia.caad.fkie.fraunhofer.de/details/win.sunburst — Cited by AI analysis.

Intel Summary

40

Techniques

44

Tools

0

Campaigns

15

IOCs

0

Observed Data

10

Tactics

Tags

Financial Targeting
APT
Cloud Threats
Cryptomining
Education Sector
Password Spraying
Azure Compromise
Credential Access
Privilege Escalation
Defense Evasion
Persistence
Multiple Platforms
Firewall Modification
Malicious Copy‑Paste
Download/Open Execution
Container Image Attack
Package Manager Misuse
Print Spooler Persistence
SUNBURST
Cloud-based Attacks

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.