Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1811

Also known as: Storm-1811, CURLY SPIDER, STAC5777, Cardinal

Description

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.(Citation: Microsoft Storm-1811 2024)(Citation: rapid7-email-bombing)(Citation: RedCanary Storm-1811 2024)(Citation: RedCanary June Insights 2024)

AI Analysis

· 2 weeks ago

Executive Summary

Storm-1811 is a financially motivated threat actor known for deploying Black Basta ransomware. The group uniquely uses email bombing techniques to overwhelm victim inboxes with non-malicious spam, prompting victims to interact with fake helpdesk links or emails leading to tool deployment.

Goals & Targeting

The group's strategic objectives revolve around financial gain through ransomware deployments. Their targeting focuses on sectors with high data value, such as healthcare, education, and manufacturing. They target organizations across multiple countries, particularly those with less mature cybersecurity defenses. The choice of victims is likely based on the ease of initial compromise and the potential for significant ransom payouts.

Enhanced Description

Storm-1811 operates with a primary focus on financial gain, utilizing Black Basta ransomware as their main tool. The group is distinctive for employing innovative social engineering tactics such as email bombing—flooding victim inboxes with high volumes of non-malicious emails to provoke a response. This strategy leads victims to engage with fake helpdesk interactions or malicious links, facilitating the deployment of adversary tools like Cobalt Strike and QakBot. These initial access methods are followed by data exfiltration and encryption for ransom. Storm-1811's operations highlight a sophisticated understanding of human factors in compromising defenses.

Key Capabilities

  • Advanced phishing and social engineering techniques, including email bombing
  • Deployment of Black Basta ransomware
  • Use of Cobalt Strike for initial access and credential dumping
  • Lateral movement using QakBot malware
  • Data encryption and exfiltration techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1667: Email Bombing
T1566.002: Spearphishing Link
T1059.003: Windows Command Shell
T1056: Input Capture
T1087.002: Domain Account

Software / Tooling

Black Basta ransomware
Cobalt Strike
QakBot malware

Campaigns & Victims

Storm-1811 has been observed targeting mid-sized organizations across various industries. Their campaigns involve overwhelming victims with emails to induce a response, followed by the deployment of malicious tools. The group demonstrates patience by waiting for victim interaction before deploying ransomware. Notable operations include the use of legitimate-looking domains for C2 communication and encryption of stolen data for subsequent ransom demands.

IOC Patterns

  • Spear-phishing emails with fake helpdesk links or attachments
  • Presence of Cobalt Strike or QakBot malware on systems
  • Encrypted files indicating Black Basta ransomware activity
  • Network traffic indicative of encrypted C2 channels

Recommended Actions

  • Implement advanced email filtering to detect and block phishing attempts
  • Monitor for suspicious network activities, such as encrypted channels or domain queries
  • Enhance user training programs to mitigate social engineering risks
  • Secure remote access points like RDP with strong authentication measures
  • Conduct regular hunts for indicators of lateral movement and exfiltration

Suggested Tags

Ransomware
Financial Crime
Email Compromise
Social Engineering
Cobalt Strike
QakBot

Confidence Assessment

High confidence in their financial motivation and toolset. Some uncertainty exists regarding exact targeting sectors and countries, though patterns suggest a focus on high-value data industries. Additional intelligence is needed to fully understand their operational scope.

ATT&CK Techniques

Stealth
7 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Microsoft Storm-1811 2024 — Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.
  2. RedCanary Storm-1811 2024 — Red Canary Intelligence. (2024, December 2). Storm-1811 exploits RMM tools to drop Black Basta ransomware. Retrieved March 14, 2025.
  3. RedCanary June Insights 2024 — The Red Canary Team. (2024, June 20). Intelligence Insights: June 2024. Retrieved March 14, 2025.
  4. rapid7-email-bombing — Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

Intel Summary

31

Techniques

4

Tools

0

Campaigns

0

IOCs

0

Observed Data

12

Tactics

Tags

Ransomware
Phishing
Financial Crime
Email Compromise
Social Engineering
Cobalt Strike
QakBot

Details

MITRE ID
G1046
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--319fd652-edde-46b2-9987-3519493989f5
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.