Storm-0249 is a financially motivated cybercriminal threat actor tracked as an initial access broker active since at least 2021. The actor is known for obtaining and brokering access to victim environments for downstream ransomware and other criminal operations, and has been linked to malware distribution involving BazaLoader, IcedID, Bumblebee, Emotet, Brute Ratel C4, and Latrodectus. Storm-0249 has also been identified as a customer of the Fox Tempest malware-signing-as-a-service operation, using fraudulently signed malware in real-world intrusions. The actor historically relied on large-scale phishing, including tax-themed lures targeting primarily U.S. organizations and individuals. Observed delivery chains used fake document-signing pages, QR-code phishing, abuse of legitimate web services, and redirection infrastructure to deliver credential theft pages or malware. By early 2025, Storm-0249 was associated with campaigns delivering Brute Ratel C4 followed by Latrodectus, and with broader ClickFix-style social engineering activity used to induce victims to execute malicious commands. Storm-0249 later shifted from noisier email-based delivery toward stealthier and more targeted intrusion methods. Since March 2025, the actor has been observed compromising legitimate websites, likely including WordPress-based sites, and using ClickFix lures to deliver Latrodectus and other initial access malware. Reporting from late 2025 indicates the group increasingly abused trusted Windows utilities and endpoint detection and response components to load malware, establish persistence, and prepare victim networks for ransomware deployment. A notable tradecraft evolution is Storm-0249’s abuse of legitimate, signed security software processes for DLL sideloading and defense evasion, including use of SentinelOne-related binaries to execute malicious code under the cover of trusted processes. Associated activity includes malicious MSI-based payload delivery, in-memory PowerShell execution, use of built-in Windows tools such as curl, reconnaissance, command-and-control enablement, and persistence mechanisms designed to survive remediation. This progression reflects Storm-0249’s role as a specialized access broker supplying ransomware-ready footholds to other criminal actors rather than operating solely as a malware distributor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named by Microsoft as a threat group that utilized malware signed through Fox Tempest's fraudulent signing service.
Named as a customer of Fox Tempest's malware-signing service.
Named as a threat actor linked to the Fox Tempest malware-signing service.
Named activity cluster observed using Fox Tempest-signed malware in real-world intrusions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.