Threat group.View on attack.mitre.org
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.
| Technique | Procedure example |
|---|---|
| T1021.002 SMB/Windows Admin Shares |
Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket. |
| T1021.004 SSH |
Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access. |
| T1027.013 Encrypted/Encoded File |
Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process. |
| T1033 System Owner/User Discovery |
Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator. |
| T1036 Masquerading |
Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations. |
| T1036.005 Match Legitimate Resource Name or Location |
Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package. |
| T1036.010 Masquerade Account Name |
Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP). |
| T1056 Input Capture |
Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item. |
| T1059.001 PowerShell |
Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server. |
| T1059.003 Windows Command Shell |
Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines. |
| T1074.001 Local Data Staging |
Storm-1811 has locally staged captured credentials for subsequent manual exfiltration. |
| T1087.002 Domain Account |
Storm-1811 has performed domain account enumeration during intrusions. |
| T1105 Ingress Tool Transfer |
Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices. |
| T1140 Deobfuscate/Decode Files or Information |
Storm-1811 has distributed password-protected archives such as ZIP files during intrusions. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.