Storm-1811 is a financially motivated cybercriminal threat cluster tracked by Microsoft and closely associated with intrusion activity that has led to Black Basta and 3AM ransomware operations. The actor has been active since at least 2022 and is known for social-engineering-heavy initial access, especially impersonating help desk or IT support personnel over Microsoft Teams, phone calls, and related remote-support workflows. A characteristic intrusion pattern involves email bombing to create urgency and confusion, followed by contact from an attacker posing as technical support who persuades the victim to launch or authorize legitimate remote access tools such as Microsoft Quick Assist and other remote monitoring and management software. After obtaining interactive access, Storm-1811 has conducted reconnaissance, credential capture, persistence, and lateral movement. Reported post-access behavior includes use of batch scripts and PowerShell, staging captured credentials for later exfiltration, creation of Registry Run keys for persistence, and deployment of remote-access and commodity malware tooling. The actor has also used malicious DLL side-loading, including modified legitimate installers and signed binaries to load Cobalt Strike beacons or other payloads. Observed tradecraft includes masquerading, abuse of legitimate administrative tools, and use of DNS-related command-and-control techniques in related activity. Storm-1811 overlaps with activity tracked by Sophos as STAC5777, and reporting has linked its operations to emerging offshoots such as UNC6692. The cluster has been tied to access operations supporting ransomware affiliates and follow-on extortion activity rather than a single exclusive malware family. In multiple investigations, Storm-1811-linked intrusions progressed rapidly from social engineering to hands-on-keyboard activity, credential theft, network discovery, lateral movement via RDP and WinRM, persistence establishment, and attempted ransomware deployment. The actor’s tradecraft is notable for exploiting trusted enterprise collaboration and support tools to bypass traditional perimeter-focused defenses.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day. The vulnerability (CVE-2024-26169) occurs in the Windows Error Reporting Service. If exploited on affected systems, it can permit an attacker to elevate their privileges.
54 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed as an example activity cluster associated with the detection's ATT&CK annotations for Linux system binary backdooring/masquerading behavior.
Mentioned only as one of many threat actors associated with the generic discovery technique of running the Linux id command.
Mentioned only as one of many named activity clusters associated with the Masquerading technique annotation in a Splunk detection entry; no campaign-specific activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.