Also known as: APOTHECARY SPIDER
Storm-1113 is a threat actor that acts both as an access broker focused on malware distribution through search advertisements and as an “as-a-service” entity providing malicious installers and landing page frameworks. In Storm-1113 malware distribution campaigns, users are directed to landing pages mimicking well-known software that host installers, often MSI files, that lead to the installation of malicious payloads. Storm-1113 is also the developer of EugenLoader, a commodity malware first observed around November 2022.
Executive Summary
Storm-1113 is an access broker and 'as-a-service' threat actor known for distributing malware through search advertisements and providing malicious installers. They are associated with the EugenLoader malware, a commodity first seen in November 2022, which targets users via fake software update pages leading to malicious MSI file downloads.
Goals & Targeting
Storm-1113's strategic objectives appear to focus on financial gain through the distribution of malware and provision of malicious tools. Their targeting profile likely includes sectors with high consumer-facing exposure, such as retail, e-commerce, or any industry where ad-based campaigns can effectively reach a broad audience. The absence of specific data on targeted countries suggests a global approach, possibly focusing on regions with active ad networks or less mature cybersecurity defenses.
Enhanced Description
Storm-1113 operates as a dual-function threat actor: part access broker and part provider of恶意软件分发工具. Their primary method involves creating search advertisements that direct unsuspecting users to malicious landing pages designed to mimic legitimate software distribution sites. These landing pages host MSI files, which when downloaded and installed, deploy malicious payloads onto the victim's system. The actor is also known for developing EugenLoader, a commodity malware that underscores their capability to create and distribute malicious tools at scale. Storm-1113's operations suggest they are focused on monetization through initial access brokering or tool-as-a-service offerings, positioning them as a mid-tier threat actor with a technical but not highly sophisticated toolkit.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
Storm-1113's campaigns typically involve large-scale ad injection and malicious software distribution. Their operational tempo appears steady, with activity observed since November 2022. Victims are likely to include individuals and organizations exposed through popular search engines or ad networks. Notable past operations include the use of EugenLoader in fraudulent software update campaigns targeting users seeking free tools or cracked software.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in the available data regarding Storm-1113's specific motivations, exact targeting criteria, and full suite of tools. Key gaps include details on their TTPs beyond malware distribution and ad-based campaigns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics