Storm-1811

MITRE ATT&CK: G1046 View on attack.mitre.org

Aliases: Storm-1811, CURLY SPIDER

First seen
2022-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:17:00

Targeted industries: financial-services technology-and-telecommunications healthcare-and-pharmaceutical retail-and-hospitality

Context

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.

Detection coverage

  • 157 YARA rules
  • 665 Sigma rules

Malware & tools used

  • Cloud Accounts (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Email Bombing (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Domains (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Tool (attack-pattern)
  • Remote Desktop Software (attack-pattern)
  • PowerShell (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Masquerade Account Name (attack-pattern)
  • Input Capture (attack-pattern)
  • DLL (attack-pattern)
  • Malicious File (attack-pattern)
  • Spearphishing Voice (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Impersonation (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • SSH (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Masquerading (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Spearphishing via Service (attack-pattern)

Related threat objects

Reports & references

  • Microsoft — Threat Actors Misusing Quick Assist In Social Engineering Attacks Leading To Ransomware (report)
  • redcanary.com — Storm 1811 Black Basta (report)
  • redcanary.com — Intelligence Insights June 2024 (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • MITRE ATT&CK — G1046 (report)
  • rapid7.com — Ongoing Social Engineering Campaign Linked To Black Basta Ransomware Operators (report)

External references