Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-2945

Also known as: APT29, Cozy Bear, tracked as, the Dukes, Nobelium, the SVR, Storm-2755, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, Alluring Pisces, 560048, Sandworm Team, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

Storm‑2945 operates as a sub‑cluster within the larger Midnight Blizzard family, exploiting both technological vulnerabilities and human factors to breach corporate defenses. Their primary vector involves hijacking public Wi‑Fi networks in hospitality venues, manipulating captive portals to deliver malware, and leveraging doppelganger Microsoft domains for device code phishing that extracts M365 credentials. Beyond initial access, the actor is known for deploying sophisticated supply‑chain tactics – notably the SolarWinds Orion compromise in 2020 – and exploiting recently disclosed SharePoint ToolShell CVEs. They also frequently inject malicious Amazon, Google, or Azure images into cloud environments to ensure a foothold that persists across provisioning cycles. The custom RAT CornFlake provides a modular set of capabilities: arbitrary code execution, credential dumping, persistence via local accounts and web shells (VersaMem), and exfiltration over cloud services. An associated FruitStone web‑based C2 panel orchestrates these activities. AI augmentation is reported to support phishing, credential harvesting, and anomaly generation. Storm‑2945 demonstrates a persistent operational tempo, rapidly pivoting between social engineering, exploitation of software vulnerabilities, and supply‑chain infiltration while maintaining a global footprint across dozens of countries and sectors.

Goals & Targeting

Targeted Sectors

Financial services
Hospitality
Government
Defense
Energy
Healthcare
Media
Telecommunications
Manufacturing
Information technology
Construction
Critical infrastructure
Transportation
Education
Non profit
Chemical
Aerospace
Maritime
Aviation
Think tank
Utilities
Oil gas
Nuclear
Legal services
Entertainment

Targeted Countries / Regions

US
RU
CN
UA
IN
IR
JP
AU
KR
GB
DE
PL
CA
VN
FR
BR
SG
TW
ES
KZ
IL
TR
MX
IT

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

Storm‑2945, also known as APT29, is a highly sophisticated threat actor that targets a broad spectrum of sectors—financial, government, hospitality, and critical infrastructure—using a blend of phishing, captive‑portal hijacking, and zero‑day exploits. The group’s operations are marked by AI‑augmented tactics, device code phishing against Microsoft Entra ID, and the deployment of a custom RAT named CornFlake. Their campaigns frequently use third‑party cloud services for command & control, data exfiltration, and malware distribution.

Goals & Targeting

The actor’s strategic objectives appear dual‑faced: short‑term financial gain through credential theft and ransomware‑style exfiltration, and long‑term espionage by embedding in critical infrastructures and harvesting intelligence via compromised Microsoft 365 environments. Their targeting profile spans sectors that routinely leverage cloud services and large user bases—such as hospitality networks—and includes government agencies due to the widespread use of Entra ID device code flows. The high degree of geographic diversity suggests a coordinated, state‑backed organization prioritizing both political influence and monetary advantage.

Enhanced Description

Key Capabilities

  • Hijacking public Wi‑Fi networks to steal M365 credentials
  • Manipulating captive portal traffic for malware delivery
  • Phishing using doppelganger domains mimicking Microsoft services
  • Abusing device code authentication flow in Microsoft Entra ID
  • Leveraging AI to augment operational tactics
  • Exploiting CVE vulnerabilities for remote code execution
  • Password spraying and credential dumping
  • Token theft and API abuse
  • Spear‑phishing for initial access
  • Supply chain intrusion via malicious software injection into build processes
  • Credential capture from compromised servers
  • Deploying web shells (VersaMem) for persistence/execution
  • Using compromised cloud accounts for exfiltration and tool upload
  • Abusing third‑party web services as C2 and exfil channels
  • Creating local accounts to maintain persistence
  • Installing malicious AMI or container images for persistence
  • Deploying the CornFlake Remote Access Trojan via spear‑phishing emails
  • Establishing backdoor C2 channel and exfiltrating data

ATT&CK Techniques

Defense impairment
1 technique
Exfiltration
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 17 IPv4 Address 1 Filename 2

References

  1. www.microsoft.com — Cited by web research for: the SVR
  2. www.microsoft.com — Cited by web research for: Storm-2755
  3. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  4. attack.mitre.org — Cited by web research for: services
  5. www.cyfirma.com — Cited by web research for: SAPPHIRE SLEET
  6. advisory.eventussecurity.com — Cited by web research for: T1547.001

Intel Summary

40

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.