Storm-1811 is a financially motivated cybercriminal threat cluster tracked by Microsoft and widely associated with social-engineering-led intrusions that enable ransomware and data-extortion operations, particularly activity linked to Black Basta and, in some reporting, 3AM-related operations. Known aliases include Curly Spider, STAC5777 overlap reporting, and the deprecated form Storm-1811. The actor has been active since at least 2022. Storm-1811 is best known for impersonating help desk or IT support personnel to obtain initial access. Its hallmark intrusion pattern combines email bombing with direct contact over Microsoft Teams, phone, or similar channels, after which operators persuade victims to launch or authorize legitimate remote support and remote monitoring tools such as Microsoft Quick Assist and other commercial remote-access software. This tradecraft abuses trusted enterprise collaboration and administration tooling rather than relying solely on traditional malware delivery, allowing the actor to gain interactive access quickly and often evade perimeter-focused defenses. Following access, Storm-1811 has conducted hands-on-keyboard post-compromise activity including reconnaissance, credential capture, local staging of stolen credentials for later exfiltration, persistence through Registry Run keys and startup mechanisms, use of batch scripts and PowerShell, and deployment of commodity and legitimate tooling. Reporting also links the actor to SSH tunnel backdoors, remote management software abuse, and acquisition of both legitimate and malicious tools for operations. In some intrusions, the actor used DLL sideloading to deploy Cobalt Strike by disguising malicious components as part of legitimate software packages, including XOR-encoded payloads decoded at runtime by a legitimate process. Observed objectives include establishing footholds for later enterprise-wide ransomware deployment, credential theft, lateral movement, and data theft. Storm-1811 activity has been tied to Black Basta ransomware deployment and to broader ransomware and data-theft extortion campaigns. Sophos reporting assessed STAC5777, which overlaps with Storm-1811, as involved in ransomware and data-theft extortion efforts and documented credential theft, keylogging, network discovery, lateral movement over RDP and WinRM, attempts to weaken defenses, and an attempted Black Basta deployment. Related reporting also links similar tradecraft to emerging offshoot activity such as UNC6692.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
48 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster tied in the article to Black Basta-style ransomware deployment using Teams-based vishing and remote access abuse.
Financially motivated cybercriminal group abusing Microsoft Teams and Quick Assist for social-engineering-based initial access and associated with deployment of Black Basta ransomware.
Referenced as part of publicly reported activity aligned with the surge in Microsoft Teams-based social-engineering intrusions.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.