Storm-1044
Aliases: DEV-1044
- Primary motivation
- financial-gain
- Sophistication
- expert
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:13:03
Targeted industries: financial-services technology-and-telecommunications government-and-public-sector
Context
Storm-1044 has been identified as part of a cyber campaign in collaboration with Twisted Spider. They employ a strategic approach, targeting specific endpoints using an initial access trojan called DanaBot. Once they gain access, Storm-1044 initiates lateral movement through Remote Desktop Protocol sign-in attempts, passing control to Twisted Spider. Twisted Spider then compromises the endpoints by introducing the CACTUS ransomware. Microsoft has detected ongoing malvertising attacks involving Storm-1044, leading to the deployment of CACTUS ransomware.
Reports & references
- twitter.com — 1730383711437283757 (report)