Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Patched Lightning

Also known as: Storm-0113, tracked as, the Newscaster Team, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, BOLDBADGER, SamSam, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

Patched Lightning operates as an advanced persistent threat that employs a sophisticated blend of supply‑chain compo­misation techniques and classic backdoor malware. The group’s hallmark is the use of well‑known RAT families such as Agent Tesla, Ghost RAT, and the widely‑publicized SolarWinds SUNBURST backdoor that facilitated the 2020 supply‑chain breach. While it remains difficult to pin a single nation state behind the act­or due to its extensive alias network, most at­trib­tions point to Russian or Chinese origin, consistent with other groups using weather‑based naming schemes. The operator’s toolset is designed for long‑term compromise: SUNBURST provides stealthy persistence within management tools, while Agent Tesla and Ghost RAT deliver privileged remote access, credential harvesting, and data exfiltration capabilities. These tools are often deployed via spear‑phishing campaigns or direct delivery to vulnerable endpoints, subsequently establishing a robust command‑and‑control channel. Patched Lightning targets an extraordinarily broad sector portfolio that includes government agencies, defense contractors, financial services, aerospace, telecommunications, healthcare, and media organizations across the United States, China, Russia, Iran, and many other jurisdictions. Their ability to adapt tool usage — from supply‑chain attack to stand‑alone RAT — suggests a nimble operational model capable of evolving to new defensive measures.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Media
Aerospace
Education
Think tank
Information technology
Maritime
Manufacturing
Pharmaceutical
Chemical
Mining
Healthcare
Legal services
Gaming
Utilities
Hospitality
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
IR
IN
RU
GB
IL
JP
DE
KR
SA
TW
KP
TR
FR
CA
VN
AU
KZ
PK
UA
PL
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
LB
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Patched Lightning is a weather‑based threat actor catalogued by Microsoft under the moniker Storm‑0113. It primarily focuses on espionage and has repeatedly leveraged supply‑chain vectors and remote access trojans to establish persistence with government, defense, and critical infrastructure targets worldwide.

Goals & Targeting

The actor’s strategic objectives center on high‑value intelligence gathering—specifically targeting state‑support diplomatic, defense, and industrial research entities. By breaching systems via both supply‑chain vectors (e.g., SUNBURST) and targeted remote access tools, Patched Lightning gains internal network visibility, facilitates credential theft, and supports covert exfiltration of strategic information that aligns with geopolitical interests of its sponsoring nation(s).

Enhanced Description

Key Capabilities

  • Backdoor malware deployment
  • Remote Access Trojan installation
  • Supply‑chain compromise via compromised software updates

MITRE ATT&CK Tactics

Supply Chain Compromise
Persistence
Command and Control

ATT&CK Techniques

T1195

Software / Tooling

SUNBURST
Agent Tesla
Ghost RAT

Campaigns & Victims

Known operations include the SolarWinds SUNBURST incident (late 2020), which exposed extensive enterprise networks, and subsequent use of Agent Tesla to harvest credentials from compromised endpoints. The group consistently selects highly protected infrastructures and leverages legitimate software supply chains when possible, indicating a preference for stealthy persistence over overt disruption. Its operational tempo appears sporadic, deploying attacks only after identifying credible target windows rather than executing continuous intrusions.

IOC Patterns

  • Malicious domain usage
  • Backdoor installation indicators
  • Remote Access Trojan activity

Recommended Actions

  • Implement rigorous patch management and validate software supply chain integrity before deployment
  • Deploy network traffic monitoring to detect anomalous command‑and‑control communications
  • Employ DNS filtering or sinkhole solutions to block known malicious domains associated with Patched Lightning
  • Conduct phishing awareness campaigns tailored to high‑risk stakeholder groups
  • Leverage multi‑factor authentication for privileged accounts to mitigate credential exfiltration

Suggested Tags

weather-based-naming
backdoor-malware
RAT-usage
supply-chain-compromise
Patched Lightning
Storm-0113

Confidence Assessment

Information on Patched Lightning is moderately reliable regarding its use of SUNBURST, Agent Tesla, and Ghost RAT; however, uncertainties remain concerning attribution details, exact timelines of activity, and the full breadth of tools employed. Further analysis of incident records, threat‑intel feeds, and internal logs is required to close these gaps.

ATT&CK Techniques

Initial Access
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. misp-galaxy.org — Cited by web research for: cpyy
  2. learn.microsoft.com — Cited by web research for: Global
  3. misp-galaxy.org — Cited by web research for: Matrix
  4. https://malpedia.caad.fkie.fraunhofer.de/details/win.sunburst — Cited by AI analysis.
  5. https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.ghost_rat — Cited by AI analysis.

Intel Summary

1

Techniques

44

Tools

0

Campaigns

19

IOCs

0

Observed Data

1

Tactics

Tags

APT
espionage
healthcare-sector
finance-sector
weather-based-naming
backdoor-malware
RAT-usage
supply-chain-compromise
Patched Lightning
Storm-0113

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.