Storm-1811
MITRE ATT&CK: G1046 View on attack.mitre.org
Aliases: Storm-1811, CURLY SPIDER
- First seen
- 2022-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:17:00
Targeted industries: financial-services technology-and-telecommunications healthcare-and-pharmaceutical retail-and-hospitality
Context
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.
Detection coverage
- 157 YARA rules
- 665 Sigma rules
Malware & tools used
- Cloud Accounts (attack-pattern)
- Local Data Staging (attack-pattern)
- Email Bombing (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Domains (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Tool (attack-pattern)
- Remote Desktop Software (attack-pattern)
- PowerShell (attack-pattern)
- Windows Command Shell (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Masquerade Account Name (attack-pattern)
- Input Capture (attack-pattern)
- DLL (attack-pattern)
- Malicious File (attack-pattern)
- Spearphishing Voice (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Impersonation (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- SSH (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Masquerading (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Spearphishing via Service (attack-pattern)
Related threat objects
- UNC4393 (threat-actor)
Reports & references
- Microsoft — Threat Actors Misusing Quick Assist In Social Engineering Attacks Leading To Ransomware (report)
- redcanary.com — Storm 1811 Black Basta (report)
- redcanary.com — Intelligence Insights June 2024 (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- MITRE ATT&CK — G1046 (report)
- rapid7.com — Ongoing Social Engineering Campaign Linked To Black Basta Ransomware Operators (report)