Storm-1811, also known as Curly Spider, is a financially motivated cybercriminal threat actor active since at least 2022. Microsoft has associated the group with Black Basta ransomware deployment; Storm-1811 activity has also been linked to delivery of 3AM ransomware. The group specializes in social-engineering initial access, particularly impersonating help-desk personnel or IT administrators. Its established intrusion pattern combines email bombing with follow-up telephone calls or external Microsoft Teams chats and calls, coercing targets into granting remote control through legitimate remote-support and remote-monitoring tools, especially Microsoft Quick Assist, and in some cases other commercial remote-access products. Following access, Storm-1811 has conducted host and network reconnaissance, credential collection and staging, lateral movement, and persistence. Observed activity includes use of batch scripts, PowerShell, SSH tunneling, and Windows Registry Run-key persistence. Storm-1811-linked operations have employed DLL side-loading to execute payloads, including Cobalt Strike, and have used malicious DLLs capable of collecting system information, credentials, and keystrokes. The group’s operational objective is to establish enterprise footholds that facilitate ransomware deployment and associated post-compromise activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day. The vulnerability (CVE-2024-26169) occurs in the Windows Error Reporting Service. If exploited on affected systems, it can permit an attacker to elevate their privileges.
54 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection's APT annotations.
Listed in the detection's Annotations section.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed as an example activity cluster associated with the detection's ATT&CK annotations for Linux system binary backdooring/masquerading behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.