Storm-3075 is a financially motivated initial access broker and malware distributor tracked by Microsoft. The actor is associated with large-scale malvertising campaigns that impersonate AI-related software and services to trick users into downloading malware. Observed lures have included fake AI plugins and other trending AI-branded tools promoted through deceptive advertising and search-driven distribution, including placements on free movie streaming sites and code-hosting platforms. Storm-3075 is assessed to deliver payloads for multiple downstream criminal actors rather than operating as a single-purpose malware crew. Reported payloads distributed by this actor include Vidar Stealer, Lumma Stealer, Hijack Loader, and Oyster. In documented campaigns, Storm-3075 used fraudulently signed malware to increase user trust and reduce early-stage detection, with part of the signing activity linked to Fox Tempest, a criminal malware-signing service provider. The actor has also used user-interaction gates such as CAPTCHA-like or “Continue” prompts to delay malicious execution and hinder sandboxing and automated analysis. The group’s tradecraft centers on initial access and malware delivery through social engineering, malvertising, and evasive staging. Campaigns have involved fake software installers, signed executables, downloader chains, and follow-on infostealer deployment. A major campaign in March 2026 reportedly affected more than 66,000 devices, with most impacted systems assessed to be consumer endpoints. The most prominently affected countries in that activity were Japan, South Africa, the United States, and France. Storm-3075 is best characterized as a cybercriminal access and distribution actor in the broader malware ecosystem, enabling credential theft, data theft, and post-compromise monetization by delivering commodity and criminal-service payloads on behalf of other financially motivated operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Runs malvertising campaigns using fake AI-themed software lures to deliver signed malware and infostealers.
Conducted a malvertising campaign using AI-themed lures, distributing a fake “Awesome AI Windows Plugin” that led victims to execute malware resulting in Vidar infostealer infection.
Initial access broker and malware distributor using AI-themed malvertising lures to deliver payloads for downstream actors, including Vidar Stealer, Lumma Stealer, Hijack Loader, and Oyster.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.