Storm-1674
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:50:28
Targeted industries: financial-services technology-and-telecommunications
Context
Storm-1674 is an access broker known for using tools based on the publicly available TeamsPhisher tool to distribute DarkGate malware. Storm-1674 campaigns have typically relied on phishing lures sent over Teams with malicious attachments, such as ZIP files containing a LNK file that ultimately drops DarkGate and Pikabot. In September 2023, Microsoft observed handoffs from Storm-1674 to ransomware operators that have led to Black Basta ransomware deployment.
Reports & references
- Microsoft — Financially Motivated Threat Actors Misusing App Installer (report)
- rewterz.com — Rewterz Threat Alert Widely Abused Msix App Installer Disabled By Microsoft Active Iocs (report)
- raw.githubusercontent.com — Microsoftmapping (report)