Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1113

Also known as: APOTHECARY SPIDER

Description

Storm-1113 is a threat actor that acts both as an access broker focused on malware distribution through search advertisements and as an “as-a-service” entity providing malicious installers and landing page frameworks. In Storm-1113 malware distribution campaigns, users are directed to landing pages mimicking well-known software that host installers, often MSI files, that lead to the installation of malicious payloads. Storm-1113 is also the developer of EugenLoader, a commodity malware first observed around November 2022.

AI Analysis

· 1 week ago

Executive Summary

Storm-1113 is an access broker and 'as-a-service' threat actor known for distributing malware through search advertisements and providing malicious installers. They are associated with the EugenLoader malware, a commodity first seen in November 2022, which targets users via fake software update pages leading to malicious MSI file downloads.

Goals & Targeting

Storm-1113's strategic objectives appear to focus on financial gain through the distribution of malware and provision of malicious tools. Their targeting profile likely includes sectors with high consumer-facing exposure, such as retail, e-commerce, or any industry where ad-based campaigns can effectively reach a broad audience. The absence of specific data on targeted countries suggests a global approach, possibly focusing on regions with active ad networks or less mature cybersecurity defenses.

Enhanced Description

Storm-1113 operates as a dual-function threat actor: part access broker and part provider of恶意软件分发工具. Their primary method involves creating search advertisements that direct unsuspecting users to malicious landing pages designed to mimic legitimate software distribution sites. These landing pages host MSI files, which when downloaded and installed, deploy malicious payloads onto the victim's system. The actor is also known for developing EugenLoader, a commodity malware that underscores their capability to create and distribute malicious tools at scale. Storm-1113's operations suggest they are focused on monetization through initial access brokering or tool-as-a-service offerings, positioning them as a mid-tier threat actor with a technical but not highly sophisticated toolkit.

Key Capabilities

  • Malware distribution via search ads and malicious landing pages
  • Development and distribution of EugenLoader malware
  • Operation as a 'tool-as-a-service' provider
  • Spear-phishing through fake software updates

MITRE ATT&CK Tactics

Initial Access (TA0001)
Defense Evasion (TA0005)
Credential Access (TA0006)

Software / Tooling

EugenLoader
Malicious MSI files

Campaigns & Victims

Storm-1113's campaigns typically involve large-scale ad injection and malicious software distribution. Their operational tempo appears steady, with activity observed since November 2022. Victims are likely to include individuals and organizations exposed through popular search engines or ad networks. Notable past operations include the use of EugenLoader in fraudulent software update campaigns targeting users seeking free tools or cracked software.

IOC Patterns

  • Spear-phishing emails with malicious links
  • Ad-based campaigns distributing MSI files
  • C2 communication via hardcoded domains

Recommended Actions

  • Implement endpoint detection and response (EDR) to identify malicious MSI file executions
  • Monitor and block known ad injection campaigns and suspicious search engine activity
  • Enhance user education on recognizing fake software download pages
  • Conduct regular supply chain security reviews for software providers

Suggested Tags

APT
malware_as_a_service
advertising_fraud
retail_sector

Confidence Assessment

Low confidence in the available data regarding Storm-1113's specific motivations, exact targeting criteria, and full suite of tools. Key gaps include details on their TTPs beyond malware distribution and ad-based campaigns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
malware_as_a_service
advertising_fraud
retail_sector

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.