Storm-1113

Aliases: APOTHECARY SPIDER

First seen
2022-11-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:34:23

Targeted industries: technology-and-telecommunications retail-and-hospitality financial-services

Context

Storm-1113 is a threat actor that acts both as an access broker focused on malware distribution through search advertisements and as an “as-a-service” entity providing malicious installers and landing page frameworks. In Storm-1113 malware distribution campaigns, users are directed to landing pages mimicking well-known software that host installers, often MSI files, that lead to the installation of malicious payloads. Storm-1113 is also the developer of EugenLoader, a commodity malware first observed around November 2022.

Reports & references

  • Microsoft — Financially Motivated Threat Actors Misusing App Installer (report)
  • raw.githubusercontent.com — Microsoftmapping (report)

External references