Storm-1044

Aliases: DEV-1044

Primary motivation
financial-gain
Sophistication
expert
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:13:03

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Context

Storm-1044 has been identified as part of a cyber campaign in collaboration with Twisted Spider. They employ a strategic approach, targeting specific endpoints using an initial access trojan called DanaBot. Once they gain access, Storm-1044 initiates lateral movement through Remote Desktop Protocol sign-in attempts, passing control to Twisted Spider. Twisted Spider then compromises the endpoints by introducing the CACTUS ransomware. Microsoft has detected ongoing malvertising attacks involving Storm-1044, leading to the deployment of CACTUS ransomware.

Reports & references

  • twitter.com — 1730383711437283757 (report)

External references