Also known as: tracked as
Storm‑1977 is a multi‑stage attacker that conducts large‑scale password‑spraying campaigns against public cloud tenants (Azure and potentially other SaaS environments). The first vector used in most observed attacks is the AzureChecker.exe command‑line tool, which scans tenant directories for accessible files and then leverages misconfigured guest accounts to expand the attack surface by creating additional resource groups within compromised subscriptions. Once inside a subscription, the actor deploys cryptomining workloads into more than 200 containers across its victims. It uses the cloud native “Container CLI/API” (MITRE T1059.013) and PowerShell scripts to pull custom images and spin up mining pipelines while masking the activity behind legitimate infrastructure resources. The persistence layer relies heavily on container‑side tactics, such as modifying LSA authentication packages, abusing the Print Spooler DLL for persistence, and hijacking default file associations. To evade detection, Storm‑1977 abuses a broad set of credential theft techniques: Kerberoasting, golden/silver ticket forging (Kerberos tickets), and the use of application access tokens. It also manipulates firewall rules, injects code via copy‑paste operations, and uses BITS jobs or Office macros to deliver payloads. The actor’s operational footprint is distinguished by its ability to archive collected data through libraries and utilities while moving laterally through component object model (COM), dynamic data exchange (DDE), and XPC services.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑1977 is a financially motivated threat actor that targets cloud tenants, primarily in the education sector, using password‑spraying and the AzureChecker.exe CLI tool to compromise containers and deploy cryptocurrency mining operations. The group leverages guest account privileges to create new resource groups within compromised subscriptions, while employing sophisticated credential theft and persistence techniques to maintain footholds.
Goals & Targeting
The primary objective of Storm‑1977 appears to be the covert deployment of cryptocurrency mining operations across highly valuable cloud infrastructures. By compromising education, financial, non‑profit, defense, mining, energy, government, think‑tank and media tenants—especially in Israel, Italy, Russia, North Korea, and India—the group seeks high‑yield workloads that can generate significant passive income while maintaining a low attack surface through guest account exploitation.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑1977 has been observed conducting repeated, high‑volume password‑spraying campaigns against Azure tenants since at least early 2023, achieving a breach rate within hundreds of accounts in targeted organizations. The actor systematically escalates privileges by leveraging guest account permissions to create new resource groups, which enables long‑term cryptomining while bypassing basic security controls that monitor only user accounts. Victims span diverse sectors—particularly education and finance—but the group also infiltrates government, defense and energy cloud environments, suggesting operational reach beyond a single industry focus. Operations show rapid deployment (within minutes of initial access) and high persistence scores due to the use of container‑level persistence primitives and LSA package abuse. Notable previous campaigns include an unnamed operation that compromised at least 200+ containers across multiple tenants in Israel and Russia, as well as a later incident targeting Italian finance services where the actor extracted extensive credentials through Kerberoasting before deploying mining workloads. The consistent pattern of guest‑account exploitation combined with advanced credential forging points to a coordinated infrastructure team rather than individual opportunists. Overall, the threat actor appears to operate at a fairly high tempo, maintaining multiple simultaneous infection vectors and focusing on cloud resource elasticity as a stealth mechanism for money generation.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate to high confidence in the documented TTPs – the behaviors have been observed across multiple reports and in diverse environments. However, gaps remain regarding the exact timeline of the actor’s first appearance, precise financial outcomes, and potential operations beyond cloud containers. Further evidence would solidify the attacker’s full scope and long‑term objectives.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
44
Tools
0
Campaigns
15
IOCs
0
Observed Data
10
Tactics