Also known as: tracked as, The Great Galveston Storm, UTA0178, Jumpy Pisces, Sandworm Team, CVE-2025-52691
Storm has surfaced only weeks ago but already demonstrates a well‑structured operational footprint. Their malware leverages publicly known web vulnerabilities such as CVE‑2025‑52691 and earlier flaws like CVE‑2014‑0322 to achieve remote code execution, then mounts persistent installations using stealthy backdoors on network appliances that typically lack endpoint detection and response. To support lateral movement, the group captures valid credentials (including those for VMware vCenter/ESXi hosts) and exploits privilege‑escalation bugs such as CVE‑2025‑29824 to deploy ransomware across high‑value targets. The threat actor combines traditional cybercrime techniques with advanced obfuscation. Payloads are encoded with single‑byte XOR and Base64, disguised as legitimate JPEG files or JavaScript executed via mshta.exe, and in memory via MSBuild. Their C2 infrastructure uses dynamic DNS providers (No-IP, Oray, "3322"), SSL tunneling domains like sslip.io/nip.io, and cloud platforms such as Cloudflare Workers and Heroku—all designed to bypass standard perimeter defenses. Storm’s operations also extend beyond the web: they deploy Android backdoors for data exfiltration and device enumeration. Their deployment of the BRICKSTORM backdoor introduces SOCKS proxy tunnel support and delayed beaconing tactics, further complicating detection. The group’s modus operandi suggests a mix of opportunistic exploitation tied to recent CVEs and targeted spearphishing campaigns designed to maximize credential harvest and ransom payouts. Overall, Storm embodies a moderately sophisticated threat actor that blends opportunistic vulnerability exploitation with a sophisticated delivery pipeline and stealthy persistence mechanisms across a broad range of high‑profile industries.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm is a medium‑sophistication criminal group focused on generating financial gain through ransomware and other extortion tactics. They target a wide range of sectors—including government, finance, defense, healthcare, critical infrastructure, education, transportation, IT, nuclear, chemical, hospitality, retail, construction, and legal services—across the US, Russia, Japan, Iran, South Korea, Ukraine, China, and France. Recent activity shows rapid exploitation of public CVEs, spearphishing campaigns, and sophisticated command‑and‑control (C2) mechanisms.
Goals & Targeting
Storm’s primary strategic objective is financial gain, realized through ransomware infections, extortion or direct monetary theft. Their targeting profile reflects a preference for organizations with critical infrastructure responsibilities and potentially valuable data—government agencies, defense contractors, healthcare providers, financial institutions, education bodies, and legal services—across both domestic (US) and foreign jurisdictions that may lack robust cyber hygiene. The actor appears to favor targets with known vulnerabilities, especially in web-facing applications and legacy systems, and applies spearphishing attachments or links to compromise initial access. By using a mix of exploit kits, spearphish campaigns, and automated backdoor deployment, Storm can efficiently pivot from one victim to another, harvest credentials for lateral movement, and maximize the impact of ransomware payloads before detection occurs.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm demonstrates a rapid operational tempo, with several campaigns launched within days of each other. Their tactics often involve targeting high‑impact sectors, securing remote code execution through public CVE exploitation, and establishing persistent backdoors on otherwise neglected network devices. The group’s use of dynamic DNS and cloud providers for C2 indicates an intent to obfuscate traffic paths and evade standard perimeter detection. Despite the brief observable history, Storm has shown proficiency in lateral movement into virtualized environments (VMware vCenter/ESXi) and deploying ransomware payloads once foothold is established. Notable past operations include the deployment of BRICKSTORM on network appliances over multiple months (average persistence exceeding 390 days), and a high‑profile delivery of ransomware through PipeMagic coupled with CVE‑2025‑29824 targeting multiple international enterprises. Overall, Storm’s patterns suggest a professionalized cybercriminal organization operating across borders with a clear focus on financial exploitation.
IOC Patterns
Recommended Actions
No observed data linked yet.
48
Techniques
47
Tools
12
Campaigns
40
IOCs
0
Observed Data
14
Tactics