Also known as: Storm-1811, CURLY SPIDER, STAC5777, Cardinal
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.(Citation: Microsoft Storm-1811 2024)(Citation: rapid7-email-bombing)(Citation: RedCanary Storm-1811 2024)(Citation: RedCanary June Insights 2024)
Executive Summary
Storm-1811 is a financially motivated threat actor known for deploying Black Basta ransomware. The group uniquely uses email bombing techniques to overwhelm victim inboxes with non-malicious spam, prompting victims to interact with fake helpdesk links or emails leading to tool deployment.
Goals & Targeting
The group's strategic objectives revolve around financial gain through ransomware deployments. Their targeting focuses on sectors with high data value, such as healthcare, education, and manufacturing. They target organizations across multiple countries, particularly those with less mature cybersecurity defenses. The choice of victims is likely based on the ease of initial compromise and the potential for significant ransom payouts.
Enhanced Description
Storm-1811 operates with a primary focus on financial gain, utilizing Black Basta ransomware as their main tool. The group is distinctive for employing innovative social engineering tactics such as email bombing—flooding victim inboxes with high volumes of non-malicious emails to provoke a response. This strategy leads victims to engage with fake helpdesk interactions or malicious links, facilitating the deployment of adversary tools like Cobalt Strike and QakBot. These initial access methods are followed by data exfiltration and encryption for ransom. Storm-1811's operations highlight a sophisticated understanding of human factors in compromising defenses.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-1811 has been observed targeting mid-sized organizations across various industries. Their campaigns involve overwhelming victims with emails to induce a response, followed by the deployment of malicious tools. The group demonstrates patience by waiting for victim interaction before deploying ransomware. Notable operations include the use of legitimate-looking domains for C2 communication and encryption of stolen data for subsequent ransom demands.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in their financial motivation and toolset. Some uncertainty exists regarding exact targeting sectors and countries, though patterns suggest a focus on high-value data industries. Additional intelligence is needed to fully understand their operational scope.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
31
Techniques
4
Tools
0
Campaigns
0
IOCs
0
Observed Data
12
Tactics