Storm-0381

Aliases: DEV-0381

First seen
2022-01-01 00:00:00
Origin
RU
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:06:38

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:ca

Context

Storm-0381 is a threat actor identified by Microsoft as a Russian cybercrime group. They are known for their use of malvertising to deploy Magniber, a type of ransomware.

Reports & references

  • Microsoft — Microsoft Digital Defense Report 2023 (report)

External references