STAC5143 is a financially motivated cybercrime threat cluster associated with social-engineering intrusions that abuse Microsoft 365 and Microsoft Teams to obtain remote access, steal data, and support ransomware or extortion activity. The cluster was identified in late 2024 and is notable for copying the Teams-based vishing and email-bombing playbook associated with Storm-1811. It has possible but unconfirmed connections to FIN7, also known as Sangria Tempest or Carbon Spider, based on overlaps in tooling and obfuscation methods. STAC5143 operations have used high-volume email bombing to pressure victims into accepting follow-up contact from fake IT support personnel over Microsoft Teams. After establishing trust, operators have persuaded victims to grant remote screen control through Teams, then used that access to open command shells and deploy additional payloads from cloud-hosted storage. Observed post-access activity includes PowerShell execution with bypass options, use of WMIC and native Windows utilities for discovery, and staged deployment of Java and Python-based malware. The malware chain attributed to STAC5143 has included Java archive payloads, a bundled Java runtime, a ProtonVPN sideload chain, and Python backdoors. Operators used a legitimate VPN client to side-load a malicious DLL and then launched Python components through a renamed interpreter. Multiple Python modules were identified as RPivot-based reverse SOCKS proxy components, including functionality to relay traffic through Tor. This tooling supports covert command-and-control, persistence of access, and post-exploitation operations inside victim environments. Observed hands-on-keyboard activity includes user and domain discovery, domain-controller enumeration, network configuration collection, and related reconnaissance using built-in administrative tools. The cluster has been assessed with high confidence as part of ransomware and data-theft extortion activity, although specific ransomware family deployment was not directly confirmed for STAC5143 itself in the supplied facts. Attribution to FIN7 remains medium-confidence and not definitive because the relevant obfuscation methods and RPivot tooling are publicly available and have been used beyond a single actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior Sophos-tracked campaign combining email bombing with Teams vishing to facilitate ransomware deployment.
A previously unreported threat cluster using email bombing, fake Microsoft Teams tech-support social engineering, Teams remote control, Java/JAR-based staging, and Python backdoors to gain access, conduct discovery, establish command and control, and support data theft and ransomware/extortion activity.
Previously unreported threat cluster using email bombing and fake Microsoft Teams tech-support social engineering to gain remote access, deploy Java and Python-based backdoors, conduct discovery, and support data theft and ransomware/extortion activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.