Storm-1674 is a financially motivated cybercriminal access broker tracked by Microsoft. The actor is associated with initial-access operations that use Microsoft Teams phishing, malicious landing pages, and abuse of the Windows App Installer and MSIX packaging workflow to deliver malware. Activity observed from late 2023 shows Storm-1674 creating attacker-controlled Microsoft 365 tenants, initiating Teams meetings, and sending meeting-chat messages that spoof collaboration and file-sharing services in order to lure targets into installing malicious applications. The actor has also used tooling derived from TeamsPhisher and has delivered malicious attachments that led to malware such as DarkGate and Pikabot. Storm-1674 has been linked to malicious installers and landing-page frameworks supplied by Storm-1113, indicating cooperation within a broader criminal ecosystem of access brokers and malware distributors. Microsoft has assessed Storm-1674’s spoofed application installs as likely leading to payloads including SectopRAT or DarkGate. The actor has also been observed using Lumma Stealer in campaigns, further aligning it with financially motivated intrusion activity centered on credential theft, session and data theft, and follow-on monetization. Storm-1674’s role is primarily upstream in the intrusion chain: establishing footholds, delivering malware, and enabling downstream ransomware operations. Microsoft reported handoffs from Storm-1674 activity to ransomware operators that culminated in Black Basta deployment. The actor’s tradecraft therefore spans phishing-based initial access, malware delivery, defense evasion through trusted-platform abuse and signed package formats, and post-compromise enablement for other criminal operators. Storm-1674 is best understood as an emerging or developing criminal cluster focused on brokering access and facilitating financially motivated intrusions rather than as a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Microsoft-tracked activity cluster described as a ransomware group that has used LummaStealer in campaigns.
Storm-1674 is an initial access broker leveraging Microsoft Teams to deploy phishing tools and malware, facilitating access for further cybercriminal activity.
Financially motivated threat actor cluster tracked by Microsoft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.