ATT&CKReferencesMicrosoft Storm-1811 2024

Microsoft Storm-1811 2024

Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1021.004
SSH
GroupStorm-1811

Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access.

T1036.010
Masquerade Account Name
GroupStorm-1811

Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing.

T1059.003
Windows Command Shell
GroupStorm-1811

Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines.

T1087.002
Domain Account
GroupStorm-1811

Storm-1811 has performed domain account enumeration during intrusions.

T1105
Ingress Tool Transfer
GroupStorm-1811

Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.

T1125
Video Capture
ToolQuick Assist

Quick Assist allows for the remote administrator to view the interactive session of the running machine, including full screen activity.

T1204.002
Malicious File
GroupStorm-1811

Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity.

T1219.002
Remote Desktop Software
GroupStorm-1811

Storm-1811 has abused multiple types of legitimate remote access software and tools, such as ScreenConnect, NetSupport Manager, and AnyDesk.

T1482
Domain Trust Discovery
GroupStorm-1811

Storm-1811 has enumerated domain accounts and access during intrusions.

T1486
Data Encrypted for Impact
GroupStorm-1811

Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments.

T1566.002
Spearphishing Link
GroupStorm-1811

Storm-1811 has distributed malicious links to victims that redirect to EvilProxy-based phishing sites to harvest credentials.

T1566.003
Spearphishing via Service
GroupStorm-1811

Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel.

T1566.004
Spearphishing Voice
GroupStorm-1811

Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access.

T1585.003
Cloud Accounts
GroupStorm-1811

Storm-1811 has created malicious accounts to enable activity via Microsoft Teams, typically spoofing various IT support and helpdesk themes.

T1588.002
Tool
GroupStorm-1811

Storm-1811 acquired various legitimate and malicious tools, such as RMM software and commodity malware packages, for operations.

T1684.001
Impersonation
GroupStorm-1811

Storm-1811 impersonates help desk and IT support personnel for phishing and social engineering purposes during initial access to victim environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.