Cardinal is a cybercrime threat actor tracked by multiple vendors as Storm-1811 and UNC4393 and is widely associated with the development and operation of the Black Basta ransomware. The group emerged in connection with Black Basta in 2022 and has been linked to mature ransomware tradecraft including privilege escalation, defense evasion, and post-compromise tooling intended to accelerate encryption and impair endpoint protection. Reported activity indicates that Cardinal has used Windows privilege-escalation exploits in Black Basta intrusions and has adopted bring-your-own-vulnerable-driver techniques to disable security products by loading a signed but vulnerable kernel driver and terminating protected security processes before file encryption. Black Basta operations attributed to Cardinal have also shown use of disguised update scripts, side-loaded loaders, and follow-on remote access tooling, indicating extended dwell time and post-exploitation capability. Cardinal has historically been closely associated with the Qakbot access ecosystem and, after Qakbot’s disruption in 2023, appears to have shifted toward using DarkGate-linked operators for initial access. Reporting also describes alleged ties between Cardinal and personnel or infrastructure associated with earlier Ryuk, Conti, and Trickbot criminal ecosystems, although subgroup structure is not clearly established from the available facts. Beyond financially motivated ransomware activity, Cardinal has also been identified as a participant in overtly pro-Russian disruptive and influence-oriented operations. It was named as the leader of the Russian Legion alliance, a coalition that also includes The White Pulse, Russian Partizan, and Inteid. Under that banner, Cardinal was linked to coercive cyber activity against Denmark centered on DDoS threats and psychological pressure tied to Danish military aid for Ukraine. Cardinal has also been cited among pro-Russian hacktivist actors claiming breaches of Israeli military-related networks and public leaks of stolen information. These reports indicate that Cardinal spans both cybercriminal ransomware operations and politically aligned disruptive campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
“The NSecKrnl driver is a Windows kernel-mode driver with a known critical security vulnerability (CVE-2025-68947), which means that it fails to verify if a user has sufficient permissions before executing commands. This allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes, by issuing crafted Input/Output Control (IOCTL) requests to the driver.”
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day. The vulnerability (CVE-2024-26169) occurs in the Windows Error Reporting Service. If exploited on affected systems, it can permit an attacker to elevate their privileges.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacktivist group claiming breaches of Israeli military networks, including the Iron Dome missile defense system.
Pro-Russian hacktivist group claiming intrusion into IDF networks and public release of allegedly leaked data.
Cybercrime group discussed in connection with analysis of the Black Basta campaign; noted as potentially returning to active operations after leaked internal chat logs in early 2025.
Leader of the Russian Legion alliance and involved in public claims of DDoS attacks against Danish targets as part of the threatened ‘OpDenmark’ campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.