Also known as: Storm-0900, UNC4122, an initial access broker, tracked as, Medicare.gov, if macros were enabled, Quishing, EtterSilent
TA584 is a sophisticated threat actor that leverages compromised legitimate accounts in large waves to achieve initial access across multiple industries—including government, finance, education, manufacturing, and defense—across Europe, North America, and Asia. Their campaigns are characterized by rapid turnover; each wave lasts only days or weeks before the actor shifts tactics, lures, and infrastructure to evade detection. Core TTPs include social engineering through brand impersonation, customizable physical mail imagery, and macro‑enabled Excel documents that embed downloader scripts or remote PowerShell instructions. TA584 frequently employs ClickFix—a popular commercial social‑engineering platform—to craft custom phishing emails with localized content and spoofed display names derived from the compromised sender accounts. The actor’s delivery infrastructure is deliberately obfuscated: URLs are routed through third‑party redirect chains or TDS filtering services (e.g., Cookie Reloaded, Keitaro), use Amazon S3 buckets or Blogspot domains for final payload hosting, and dynamically change query parameters to defeat signature‑based blocking. New malware families—Tsundere Bot, a versatile backdoor with ransomware primitives, and XWorm with the "P0WER" configuration—have been introduced in 2025. TA584 also harnesses a catalog of exploitation tools such as Mimikatz for credential theft, certutil for benign-looking payload fetching, and PsExec for lateral movement. The actor’s campaigns maintain a consistent financial objective: rapid credential acquisition and opportunistic ransomware‑delivery, often targeting high‑profile entities to maximize the perceived value of stolen data. By exploiting compromised accounts, they reduce friction and avoid direct attribution, while their modular toolset enables quick adaptation to security postures and emerging defensive controls.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TA584, also known as Storm‑0900 and UNC4122, is a high-volume initial access broker that targets a broad range of sectors worldwide using macro‑enabled Office attachments, brand impersonation, and rapid campaign churn. The group recently added the Tsundere Bot malware family and expanded its geographic scope to include Germany and Australia while maintaining operations in North America. Financial gain remains the primary motivation, with attacks designed for quick credential harvests and potential ransomware delivery.
Goals & Targeting
TA584’s strategic objective is primarily financial gain through large‑scale credential theft, phishing‑based initial compromise, and opportunistic ransomware deployments. The actor targets a diversified portfolio of sectors—including government agencies, defense contractors, educational institutions, media outlets, and healthcare providers—to maximize attack surface and potential payout. Geographically, TA584 has maintained a presence in the United States and Europe while recently expanding operations to Australia, Germany, Poland, Russia, Japan, and other markets. By rapidly rotating brand lures, localized content, and delivery vectors, the group avoids pattern recognition and increases the likelihood of successful compromise across diverse organizations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA584’s campaign cadence demonstrates a high‑volume, hit‑and‑miss approach: each wave harnesses thousands of compromised legitimate accounts to distribute macro‑enabled email attachments and malicious URLs. Attackers rotate brand identities daily or weekly, localizing content linguistically to match targeted regions and ensuring that the same host appears fresh with every new phishing burst. The group’s infrastructure layers include third‑party TDS services, cloud storage on Amazon S3, and user‑generated Blogspot pages, all fed through redirect chains that dynamically change query strings—a tactic that hampers static IOC correlation. Notable operations have seen the actor impersonate well‑known payroll service ADP or use customized physical mail photos to increase realism. The new Tsundere Bot and XWorm variants hint at a strategic shift toward ransomware payloads, suggesting an escalation in monetary focus while maintaining low cost of acquisition via compromised accounts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core TTPs, malware families, and campaign patterns is high due to multiple independent reports and corroborating IOC evidence. However, specific attribution timelines, precise infrastructure ownership (e.g., exact compromised domain catalogs), and definitive proof of ransomware delivery attempts remain partially inferred, leaving gaps in fully mapping operational footprints across all known campaigns.
No campaigns linked yet.
No observed data linked yet.
47
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
15
Tactics