Also known as: APT29, Cozy Bear, tracked as, the Dukes, Nobelium, the SVR, Storm-2755, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, Alluring Pisces, 560048, Sandworm Team, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
Storm‑2945 operates as a sub‑cluster within the larger Midnight Blizzard family, exploiting both technological vulnerabilities and human factors to breach corporate defenses. Their primary vector involves hijacking public Wi‑Fi networks in hospitality venues, manipulating captive portals to deliver malware, and leveraging doppelganger Microsoft domains for device code phishing that extracts M365 credentials. Beyond initial access, the actor is known for deploying sophisticated supply‑chain tactics – notably the SolarWinds Orion compromise in 2020 – and exploiting recently disclosed SharePoint ToolShell CVEs. They also frequently inject malicious Amazon, Google, or Azure images into cloud environments to ensure a foothold that persists across provisioning cycles. The custom RAT CornFlake provides a modular set of capabilities: arbitrary code execution, credential dumping, persistence via local accounts and web shells (VersaMem), and exfiltration over cloud services. An associated FruitStone web‑based C2 panel orchestrates these activities. AI augmentation is reported to support phishing, credential harvesting, and anomaly generation. Storm‑2945 demonstrates a persistent operational tempo, rapidly pivoting between social engineering, exploitation of software vulnerabilities, and supply‑chain infiltration while maintaining a global footprint across dozens of countries and sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑2945, also known as APT29, is a highly sophisticated threat actor that targets a broad spectrum of sectors—financial, government, hospitality, and critical infrastructure—using a blend of phishing, captive‑portal hijacking, and zero‑day exploits. The group’s operations are marked by AI‑augmented tactics, device code phishing against Microsoft Entra ID, and the deployment of a custom RAT named CornFlake. Their campaigns frequently use third‑party cloud services for command & control, data exfiltration, and malware distribution.
Goals & Targeting
The actor’s strategic objectives appear dual‑faced: short‑term financial gain through credential theft and ransomware‑style exfiltration, and long‑term espionage by embedding in critical infrastructures and harvesting intelligence via compromised Microsoft 365 environments. Their targeting profile spans sectors that routinely leverage cloud services and large user bases—such as hospitality networks—and includes government agencies due to the widespread use of Entra ID device code flows. The high degree of geographic diversity suggests a coordinated, state‑backed organization prioritizing both political influence and monetary advantage.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
40
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics