Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: tracked as, The Great Galveston Storm, UTA0178, Jumpy Pisces, Sandworm Team, CVE-2025-52691

Description

Storm has surfaced only weeks ago but already demonstrates a well‑structured operational footprint. Their malware leverages publicly known web vulnerabilities such as CVE‑2025‑52691 and earlier flaws like CVE‑2014‑0322 to achieve remote code execution, then mounts persistent installations using stealthy backdoors on network appliances that typically lack endpoint detection and response. To support lateral movement, the group captures valid credentials (including those for VMware vCenter/ESXi hosts) and exploits privilege‑escalation bugs such as CVE‑2025‑29824 to deploy ransomware across high‑value targets. The threat actor combines traditional cybercrime techniques with advanced obfuscation. Payloads are encoded with single‑byte XOR and Base64, disguised as legitimate JPEG files or JavaScript executed via mshta.exe, and in memory via MSBuild. Their C2 infrastructure uses dynamic DNS providers (No-IP, Oray, "3322"), SSL tunneling domains like sslip.io/nip.io, and cloud platforms such as Cloudflare Workers and Heroku—all designed to bypass standard perimeter defenses. Storm’s operations also extend beyond the web: they deploy Android backdoors for data exfiltration and device enumeration. Their deployment of the BRICKSTORM backdoor introduces SOCKS proxy tunnel support and delayed beaconing tactics, further complicating detection. The group’s modus operandi suggests a mix of opportunistic exploitation tied to recent CVEs and targeted spearphishing campaigns designed to maximize credential harvest and ransom payouts. Overall, Storm embodies a moderately sophisticated threat actor that blends opportunistic vulnerability exploitation with a sophisticated delivery pipeline and stealthy persistence mechanisms across a broad range of high‑profile industries.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Financial services
Defense
Healthcare
Critical infrastructure
Education
Transportation
Information technology
Nuclear
Chemical
Hospitality
Retail
Construction
Legal services

Targeted Countries / Regions

US
RU
JP
IR
KR
UA
CN
FR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 4 days ago

Executive Summary

Storm is a medium‑sophistication criminal group focused on generating financial gain through ransomware and other extortion tactics. They target a wide range of sectors—including government, finance, defense, healthcare, critical infrastructure, education, transportation, IT, nuclear, chemical, hospitality, retail, construction, and legal services—across the US, Russia, Japan, Iran, South Korea, Ukraine, China, and France. Recent activity shows rapid exploitation of public CVEs, spearphishing campaigns, and sophisticated command‑and‑control (C2) mechanisms.

Goals & Targeting

Storm’s primary strategic objective is financial gain, realized through ransomware infections, extortion or direct monetary theft. Their targeting profile reflects a preference for organizations with critical infrastructure responsibilities and potentially valuable data—government agencies, defense contractors, healthcare providers, financial institutions, education bodies, and legal services—across both domestic (US) and foreign jurisdictions that may lack robust cyber hygiene. The actor appears to favor targets with known vulnerabilities, especially in web-facing applications and legacy systems, and applies spearphishing attachments or links to compromise initial access. By using a mix of exploit kits, spearphish campaigns, and automated backdoor deployment, Storm can efficiently pivot from one victim to another, harvest credentials for lateral movement, and maximize the impact of ransomware payloads before detection occurs.

Enhanced Description

Key Capabilities

  • Exploits multiple web vulnerabilities (CVE‑2014‑0322, CVE‑2011‑0611, CVE‑2025‑52691, etc.)
  • Utilizes spearphishing attachments and links via email
  • Executes malicious JavaScript through mshta.exe
  • Encodes payloads with single‑byte XOR and Base64
  • Disguises executables as JPG files
  • Deploys Android backdoors for data exfiltration and device enumeration
  • Uses dynamic DNS providers (No‑IP, Oray, 3322) to host command and control
  • Deploys stealthy backdoors on network appliances lacking EDR
  • Uses SOCKS proxy functionality for tunneling
  • Implements delay timers with hard‑coded future dates before beaconing
  • Obfuscates binaries using Garble and custom wssoft library
  • Captures valid credentials to pivot laterally to VMware vCenter/ESXi hosts
  • Exploits CVE‑2025‑29824 to elevate privileges and deploy ransomware
  • Downloads malicious payloads via certutil from compromised websites
  • Uses in‑memory execution of malicious MSBuild files

MITRE ATT&CK Tactics

Initial Access
Execution
Exfiltration
Persistence
Defense Evasion
Credential Access
Lateral Movement
Privilege Escalation
Command and Control

ATT&CK Techniques

T1566.001
T1566.002
T1203
T1027
T1027.003
T1041
T1078.001
T1068
T1105
T1086
T1071

Software / Tooling

mshta.exe
DeployJava.js
BRICKSTORM
PipeMagic
certutil
MSBuild
Garble
wssoft library
Cloudflare Workers
Heroku

Campaigns & Victims

Storm demonstrates a rapid operational tempo, with several campaigns launched within days of each other. Their tactics often involve targeting high‑impact sectors, securing remote code execution through public CVE exploitation, and establishing persistent backdoors on otherwise neglected network devices. The group’s use of dynamic DNS and cloud providers for C2 indicates an intent to obfuscate traffic paths and evade standard perimeter detection. Despite the brief observable history, Storm has shown proficiency in lateral movement into virtualized environments (VMware vCenter/ESXi) and deploying ransomware payloads once foothold is established. Notable past operations include the deployment of BRICKSTORM on network appliances over multiple months (average persistence exceeding 390 days), and a high‑profile delivery of ransomware through PipeMagic coupled with CVE‑2025‑29824 targeting multiple international enterprises. Overall, Storm’s patterns suggest a professionalized cybercriminal organization operating across borders with a clear focus on financial exploitation.

IOC Patterns

  • CVE-2025-52691
  • SmarterMail upload arbitrary files RCE
  • Base64 encoded payloads
  • Single-byte XOR encoded payloads
  • Executable disguised as JPG file
  • Hard‑coded date delay timer before beaconing
  • C2 via Cloudflare Workers
  • C2 via Heroku applications
  • C2 resolution through sslip.io or nip.io domains
  • Exploitation of CVE-2025-29824 elevation vulnerability
  • Download and execution of malicious MSBuild file using certutil

Recommended Actions

  • Patch all known CVE vulnerabilities (e.g., CVE‑2025‑52691, CVE‑2011‑0611, CVE‑2014‑0322) promptly
  • Implement advanced email filtering to block spearphishing attachments and links
  • Monitor and restrict the execution of mshta.exe in corporate environments
  • Enforce script-blocking policies and whitelist legitimate JavaScript execution

ATT&CK Techniques

Impact
1 technique
Reconnaissance
1 technique
1 technique

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. fortiguard.fortinet.com — Cited by web research for: CVE-2025-52691
  3. cloud.google.com — Cited by web research for: T1071.001
  4. attack.mitre.org — Cited by web research for: Backdoors
  5. www.microsoft.com — Cited by web research for: Microsoft Defender XDR

Intel Summary

48

Techniques

47

Tools

12

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
United States (US)
Confidence
80%
First Seen
Aug 3, 2026
Last Seen
Aug 10, 2026
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.