Storm-0569 is a financially motivated cybercrime cluster tracked by Microsoft and associated with Zloader and BATLOADER-related activity. The actor is best characterized as an access broker that uses malvertising and SEO poisoning to lure victims to spoofed software download pages, including pages impersonating widely used remote access, collaboration, and productivity software. Storm-0569 has abused Windows App Installer and malicious MSIX packages as an initial access vector, including delivery through the ms-appinstaller URI scheme, and has also been linked to broader MSIX package abuse campaigns. Observed infection chains commonly rely on user-driven installation of trojanized software, followed by PowerShell and batch-script execution to retrieve additional payloads. Reported follow-on tooling and malware associated with Storm-0569 includes BATLOADER, IcedID, Cobalt Strike Beacon, and remote monitoring and management tools. In at least one documented intrusion, activity attributed to Storm-0569 included data exfiltration using Rclone before a handoff that culminated in Black Basta ransomware deployment by another actor. Microsoft has also linked Storm-0569 activity to handoffs to ransomware operators including Storm-0506 and Storm-0846, reinforcing its role as an intrusion-enablement and payload-delivery actor rather than solely a ransomware operator. Tradecraft associated with Storm-0569 includes abuse of search advertisements, SEO poisoning, spoofing of legitimate brands and software download portals, malicious MSIX packaging, use of legitimate installer frameworks, scripted payload staging, and post-compromise delivery of commodity and intrusion-enablement malware. Separate reporting has described overlapping MSIX-based intrusion clusters using Advanced Installer components, compiled Python payloads, decryption utilities, and privilege-seeking scripts, with overlaps to Zloader and BATLOADER activity that align with Storm-0569. The actor's operations are opportunistic and financially motivated, with victimization spanning multiple industries rather than a narrowly defined vertical focus.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor/activity cluster leveraging MSIX package abuse.
Used a similar PowerShell-based technique to disable security protections and deploy Royal ransomware in late 2022.
Referenced as a threat actor/activity cluster leveraging MSIX packages for malware delivery.
Observed in threat campaigns abusing MSIX packages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.