Storm-1811
Overview
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.
Naming & attribution
Storm-1811 is tracked under 1 names across the industry. It uses 31 documented ATT&CK techniques — more than 67% of the 174 groups tracked here.
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1566.004Spearphishing Voice — used by 1 of 174 groups -
T1585.003Cloud Accounts — used by 1 of 174 groups -
T1667Email Bombing — used by 1 of 174 groups -
T1222.001Windows Permissions — used by 2 of 174 groups -
T1056Input Capture — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- WIRTE — 12 shared techniques (27% overlap)
- menuPass China — 14 shared techniques (22% overlap)
- APT39 Iran — 14 shared techniques (20% overlap)
- Sidewinder India — 10 shared techniques (20% overlap)
- MuddyWater Iran — 16 shared techniques (19% overlap)
- MirrorFace China — 12 shared techniques (19% overlap)
Malware families with current indicators
2 families attributed to Storm-1811, carrying 403 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- QakBot 360 indicators
- BlackBasta 43 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 31 techniques across 12 tactics
Resource Development
-
T1583.001Domains -
T1585.003Cloud Accounts -
T1588.002Tool
Initial Access
-
T1566.002Spearphishing Link -
T1566.003Spearphishing via Service -
T1566.004Spearphishing Voice
Execution
-
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027.013Encrypted/Encoded File -
T1036Masquerading -
T1036.005Match Legitimate Resource Name or Location -
T1036.010Masquerade Account Name -
T1140Deobfuscate/Decode Files or Information -
T1574.001DLL -
T1684.001Impersonation
Defense Impairment
-
T1222.001Windows Permissions
Discovery
-
T1033System Owner/User Discovery -
T1087.002Domain Account -
T1482Domain Trust Discovery
Lateral Movement
-
T1021.002SMB/Windows Admin Shares -
T1021.004SSH -
T1570Lateral Tool Transfer
Collection
-
T1056Input Capture -
T1074.001Local Data Staging
Command and Control
-
T1105Ingress Tool Transfer -
T1219.002Remote Desktop Software
Exfiltration
Impact
-
T1486Data Encrypted for Impact -
T1667Email Bombing
Tools & malware (7)
Black Basta · Cobalt Strike · Quick Assist · BITSAdmin · PsExec · Impacket · QakBot
Reporting (3)
- Storm-1811 exploits RMM tools to drop Black Basta ransomware — Red Canary Intelligence
- Intelligence Insights: June 2024 — The Red Canary Team
- Threat actors misusing Quick Assist in social engineering attacks leading to ransomware — Microsoft Threat Intelligence