ATT&CKGroupsStorm-1811

Storm-1811

G1046

Threat group.View on attack.mitre.org

About this group

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1021.002
SMB/Windows Admin Shares

Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket.

T1021.004
SSH

Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access.

T1027.013
Encrypted/Encoded File

Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process.

T1033
System Owner/User Discovery

Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator.

T1036
Masquerading

Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations.

T1036.005
Match Legitimate Resource Name or Location

Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package.

T1036.010
Masquerade Account Name

Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP).

T1056
Input Capture

Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item.

T1059.001
PowerShell

Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server.

T1059.003
Windows Command Shell

Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines.

T1074.001
Local Data Staging

Storm-1811 has locally staged captured credentials for subsequent manual exfiltration.

T1087.002
Domain Account

Storm-1811 has performed domain account enumeration during intrusions.

T1105
Ingress Tool Transfer

Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.

T1140
Deobfuscate/Decode Files or Information

Storm-1811 has distributed password-protected archives such as ZIP files during intrusions.

View all 31 procedure examples

Software7

Campaigns0

None recorded.

References4

  1. Microsoft Storm-1811 2024 Open source
    Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.
  2. RedCanary June Insights 2024 Open source
    The Red Canary Team. (2024, June 20). Intelligence Insights: June 2024. Retrieved March 14, 2025.
  3. RedCanary Storm-1811 2024 Open source
    Red Canary Intelligence. (2024, December 2). Storm-1811 exploits RMM tools to drop Black Basta ransomware. Retrieved March 14, 2025.
  4. rapid7-email-bombing Open source
    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.