Storm-1811, also known as Blitz Brigantine and STAC5777, is a financially motivated intrusion cluster associated with Black Basta and Cactus ransomware operations. The actor is known for social-engineering-led initial access, particularly email bombing followed by impersonation of internal IT or help-desk personnel over Microsoft Teams, then persuading targets to launch Quick Assist to grant remote access. This tradecraft has been used against organizations in finance and healthcare and has supported follow-on malware deployment and ransomware activity. Recent activity attributed to this cluster shows a shift toward more customized and stealth-focused post-access tooling. After obtaining remote access, the operators deploy digitally signed MSI installers masquerading as legitimate Microsoft software updates. These packages place legitimate Microsoft-signed binaries alongside attacker-controlled DLLs to achieve DLL sideloading, including abuse of components such as hostfxr.dll and clipsp.dll. The loader chain uses anti-analysis and defense-evasion measures including junk thread creation, debugger checks, virtualization and sandbox detection, environmental keying, and time-windowed decryption before executing an in-memory backdoor known as A0Backdoor. A0Backdoor fingerprints compromised hosts and uses covert DNS tunneling for command and control, including MX-record-based exchanges through trusted public recursive resolvers to reduce direct endpoint contact with attacker-controlled infrastructure. Reporting also assesses the backdoor as a precursor capability for reconnaissance, persistence, lateral movement, and eventual ransomware deployment. Across observed campaigns, Storm-1811 has demonstrated strong emphasis on social engineering, signed malware delivery, DLL sideloading, stealthy command and control, and post-compromise intrusion enablement in support of financially driven extortion ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware affiliate activity using the A0Backdoor family as a precursor for intrusion, persistence, reconnaissance, lateral movement, and eventual Black Basta or Cactus ransomware deployment. The campaign uses Teams vishing, Quick Assist abuse, trojanized MSI installers, DLL sideloading, and DNS MX tunneling for covert C2.
Social-engineering-led initial access (Microsoft Teams impersonation / fake internal IT support) followed by deployment of malicious MSI installers and DLL sideloading to load a multi-stage payload culminating in A0Backdoor; historically linked in the article to follow-on ransomware operations.
Conducting social-engineering intrusions against finance and healthcare employees by impersonating internal IT support, using email bombing and Microsoft Teams to obtain Quick Assist remote access, then deploying a stealthy loader and A0Backdoor for persistence and information theft.
Financially motivated intrusion cluster using Microsoft Teams impersonation and Windows Quick Assist social engineering to gain remote access, then deploying signed MSI-based loaders/backdoors and (in prior documented chains) follow-on tooling leading to ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.