Storm-1674

Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:50:28

Targeted industries: financial-services technology-and-telecommunications

Context

Storm-1674 is an access broker known for using tools based on the publicly available TeamsPhisher tool to distribute DarkGate malware. Storm-1674 campaigns have typically relied on phishing lures sent over Teams with malicious attachments, such as ZIP files containing a LNK file that ultimately drops DarkGate and Pikabot. In September 2023, Microsoft observed handoffs from Storm-1674 to ransomware operators that have led to Black Basta ransomware deployment.

Reports & references

  • Microsoft — Financially Motivated Threat Actors Misusing App Installer (report)
  • rewterz.com — Rewterz Threat Alert Widely Abused Msix App Installer Disabled By Microsoft Active Iocs (report)
  • raw.githubusercontent.com — Microsoftmapping (report)

External references