Storm-1811, also known as Curly Spider, is a financially motivated threat actor tracked by Microsoft. The content describes the group as active since 2022 and associated with Black Basta ransomware deployment, with some reporting also linking related activity to 3AM ransomware and emerging offshoots such as UNC6692. Sophos reporting states that STAC5777 overlaps with Storm-1811. Storm-1811 is characterized by social-engineering-driven initial access. The group impersonates help desk or IT support personnel, including through Microsoft Teams, phone calls, and similar contact, often after email-bombing victims to create urgency and confusion. The actor commonly persuades victims to launch or authorize legitimate remote monitoring and management or remote-support tools, especially Microsoft Quick Assist, and also AnyDesk, TeamViewer, Supremo, ScreenConnect, and other RMM software. Post-access activity described in the content includes reconnaissance, credential capture and local staging of captured credentials for later exfiltration, use of PowerShell and multiple batch scripts, creation of Windows Registry Run keys for persistence, and acquisition of both legitimate and malicious tooling. Reported tooling and tradecraft include use of Cobalt Strike, including installers disguised as a malicious DLL masquerading as part of a legitimate 7-Zip installation package, with an XOR-encoded payload decoded by a hardcoded key when invoked by the legitimate process. The group has also distributed password-protected ZIP archives, prompted users to execute downloaded software and payloads, established SSH tunnel backdoors, and in some cases progressed to lateral movement and ransomware deployment. The content states Storm-1811 has gained initial access to groups such as UNC2500, UNC2633, and UNC5155 to distribute ransomware such as Black Basta and 3AM.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
48 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster tied in the article to Black Basta-style ransomware deployment using Teams-based vishing and remote access abuse.
Financially motivated cybercriminal group abusing Microsoft Teams and Quick Assist for social-engineering-based initial access and associated with deployment of Black Basta ransomware.
Referenced as part of publicly reported activity aligned with the surge in Microsoft Teams-based social-engineering intrusions.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.