NEW: Group Profiler — instant APT intel lookup. Try it →
Emblem illustrating the Storm-1811 threat group

Storm-1811

Overview

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.

Naming & attribution

It uses 31 documented ATT&CK techniques — more than 67% of the 174 groups tracked here.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1566.004 Spearphishing Voice — used by 1 of 174 groups
  • T1585.003 Cloud Accounts — used by 1 of 174 groups
  • T1667 Email Bombing — used by 1 of 174 groups
  • T1222.001 Windows Permissions — used by 2 of 174 groups
  • T1056 Input Capture — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • WIRTE — 12 shared techniques (27% overlap)
  • menuPass China — 14 shared techniques (22% overlap)
  • APT39 Iran — 14 shared techniques (20% overlap)
  • Sidewinder India — 10 shared techniques (20% overlap)
  • MuddyWater Iran — 16 shared techniques (19% overlap)
  • MirrorFace China — 12 shared techniques (19% overlap)

Malware families with tracked indicators

One family attributed to Storm-1811, with 3 deduplicated indicators observed across abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL over the corpus's window (up to three years, as of 2026-09-26). MITRE documents what a group does; these are the indicators its malware families have surfaced in that window.

  • BlackBasta 3 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Custom malware/implant development — ATT&CK: 3 attributed custom malware families

TTPs — 31 techniques across 12 tactics

Resource Development

Initial Access

Execution

Persistence

Defense Impairment

Lateral Movement

Collection

Command and Control

Tools & malware (7)

Black Basta · Cobalt Strike · Quick Assist · BITSAdmin · PsExec · Impacket · QakBot

Reporting (3)