STAC5777 is a financially motivated intrusion cluster associated with Microsoft Teams and Quick Assist social-engineering campaigns that overlap with Microsoft’s Storm-1811 tracking. The actor has been linked to ransomware and data-theft extortion activity and has operational ties to ecosystems associated with Black Basta and 3AM. Its tradecraft centers on email bombing followed by impersonation of internal IT or help-desk staff over Microsoft Teams, persuading victims to grant remote access or install remote-support tooling. After initial access, the actor has deployed malware through DLL sideloading using a legitimate Microsoft-signed executable to load a malicious winhttp.dll, established persistence through services and startup shortcuts, and stored command-and-control configuration in the registry. Observed post-compromise behavior includes hands-on-keyboard activity, system and network discovery, credential theft, keylogging, scanning for SMB, RDP, and WinRM targets, lateral movement using compromised credentials, VPN access, RDP, and WinRM, and attempts to weaken defenses by uninstalling multifactor-authentication components or endpoint protection. The actor has also searched for password-related files and network diagrams to support further movement and access expansion. In at least one observed intrusion, the cluster attempted to deploy Black Basta ransomware, and reporting has assessed the broader campaign pattern as part of ransomware and data-theft extortion operations. STAC5777 is distinct from STAC5143, another cluster using a similar Teams-vishing playbook, but STAC5777 is characterized by heavier direct operator interaction and scripted command execution. Known aliases and related designations include STAC5777, STAC5777 (suspected early phase alignment), and Storm-1811.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior Sophos-tracked campaign combining email bombing with Teams vishing to facilitate ransomware deployment.
A highly active threat cluster using email bombing and fake Teams-based IT support lures to convince users to install Quick Assist, followed by hands-on-keyboard malware deployment, persistence, credential theft, lateral movement, data theft, and in at least one case attempted Black Basta ransomware deployment.
Threat cluster using email bombing, Microsoft Teams social engineering, and Quick Assist remote access to deploy a DLL side-loading backdoor, steal credentials, move laterally with RDP and WinRM, and in at least one case attempt Black Basta ransomware deployment.
Threat cluster associated with Microsoft Teams-based vishing and voice phishing techniques overlapping with 3AM-linked activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.