Storm-1084
Aliases: DEV-1084
- Origin
- IR
- Primary motivation
- sabotage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:54:18
Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications
Context
Storm-1084 is a threat actor that has been observed collaborating with the MuddyWater group. They have used the DarkBit persona to mask their involvement in targeted attacks. Storm-1084 has been linked to destructive actions, including the encryption of on-premise devices and deletion of cloud resources. They have been observed using tools such as Rport, Ligolo, and a customized PowerShell backdoor. The extent of their autonomy or collaboration with other Iranian threat actors is currently unclear.
Reports & references
- Microsoft — Mercury And Dev 1084 Destructive Attack On Hybrid Environment (report)
- circleid.com — 20230824 Signs Of Muddywater Developments Found In The Dns (report)