Also known as: Storm-0113, tracked as, the Newscaster Team, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, BOLDBADGER, SamSam, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
Patched Lightning operates as an advanced persistent threat that employs a sophisticated blend of supply‑chain compomisation techniques and classic backdoor malware. The group’s hallmark is the use of well‑known RAT families such as Agent Tesla, Ghost RAT, and the widely‑publicized SolarWinds SUNBURST backdoor that facilitated the 2020 supply‑chain breach. While it remains difficult to pin a single nation state behind the actor due to its extensive alias network, most attribtions point to Russian or Chinese origin, consistent with other groups using weather‑based naming schemes. The operator’s toolset is designed for long‑term compromise: SUNBURST provides stealthy persistence within management tools, while Agent Tesla and Ghost RAT deliver privileged remote access, credential harvesting, and data exfiltration capabilities. These tools are often deployed via spear‑phishing campaigns or direct delivery to vulnerable endpoints, subsequently establishing a robust command‑and‑control channel. Patched Lightning targets an extraordinarily broad sector portfolio that includes government agencies, defense contractors, financial services, aerospace, telecommunications, healthcare, and media organizations across the United States, China, Russia, Iran, and many other jurisdictions. Their ability to adapt tool usage — from supply‑chain attack to stand‑alone RAT — suggests a nimble operational model capable of evolving to new defensive measures.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Patched Lightning is a weather‑based threat actor catalogued by Microsoft under the moniker Storm‑0113. It primarily focuses on espionage and has repeatedly leveraged supply‑chain vectors and remote access trojans to establish persistence with government, defense, and critical infrastructure targets worldwide.
Goals & Targeting
The actor’s strategic objectives center on high‑value intelligence gathering—specifically targeting state‑support diplomatic, defense, and industrial research entities. By breaching systems via both supply‑chain vectors (e.g., SUNBURST) and targeted remote access tools, Patched Lightning gains internal network visibility, facilitates credential theft, and supports covert exfiltration of strategic information that aligns with geopolitical interests of its sponsoring nation(s).
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Known operations include the SolarWinds SUNBURST incident (late 2020), which exposed extensive enterprise networks, and subsequent use of Agent Tesla to harvest credentials from compromised endpoints. The group consistently selects highly protected infrastructures and leverages legitimate software supply chains when possible, indicating a preference for stealthy persistence over overt disruption. Its operational tempo appears sporadic, deploying attacks only after identifying credible target windows rather than executing continuous intrusions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Information on Patched Lightning is moderately reliable regarding its use of SUNBURST, Agent Tesla, and Ghost RAT; however, uncertainties remain concerning attribution details, exact timelines of activity, and the full breadth of tools employed. Further analysis of incident records, threat‑intel feeds, and internal logs is required to close these gaps.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
44
Tools
0
Campaigns
19
IOCs
0
Observed Data
1
Tactics