Storm-1113 is a financially motivated cybercrime cluster associated with the FakeBat malware ecosystem and tracked under the alias Apothecary Spider. The actor has been linked to malware delivery operations that abuse Windows MSIX packaging and the ms-appinstaller/App Installer mechanism, typically using malvertising, search-engine optimization poisoning, and spoofed software download pages that impersonate widely used applications such as Zoom. Microsoft has also described Storm-1113 as both an access broker using search advertisements and an as-a-service provider supplying malicious installers and landing-page frameworks to other criminal actors. A core element of Storm-1113 activity is EugenLoader, a malicious installer framework first observed around November 2022 and identified as developed by this actor. EugenLoader has been used to deliver a range of follow-on payloads including Gozi, RedLine Stealer, IcedID, Smoke Loader, NetSupport Manager, Sectop RAT, and Lumma Stealer. Reporting also links Storm-1113 to FakeBat-style delivery chains involving Advanced Installer-created MSIX packages, PowerShell execution via legitimate installer components, decryption and decompression stages, and delivery of stealers such as ArechClient2/RedLine as well as DLL-sideloading payloads consistent with GHOSTPULSE. Storm-1113 has used malicious signed MSIX packages as an initial-access vector and has leveraged legitimate Windows installation workflows to reduce user suspicion and bypass some browser and SmartScreen-style protections. Observed tradecraft includes social-engineering-driven initial access, malicious file execution, PowerShell-based staging, use of loader frameworks, delivery of commodity stealers and remote-access tools, and provision of installer infrastructure to other actors. The actor has also been observed using Lumma Stealer in campaigns, consistent with broader financially motivated credential and data theft activity. Storm-1113 is notable not only for conducting its own malware delivery operations but also for enabling downstream intrusions by other criminal groups. Its installer and landing-page frameworks have been used by actors such as Sangria Tempest and Storm-1674, including operations that can progress to targeted extortion or ransomware deployment. The actor’s overall profile is that of a cybercriminal malware distributor and access facilitator focused on scalable infection chains, credential theft, and post-compromise monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor/activity cluster leveraging MSIX package abuse.
Microsoft-tracked activity cluster described as a ransomware group that has used LummaStealer in campaigns.
Referenced as a threat actor/activity cluster leveraging MSIX packages for malware delivery.
Observed in threat campaigns abusing MSIX packages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.