Storm-0844 is a financially motivated cybercrime threat actor associated with ransomware operations. The cluster has been historically tied to Akira ransomware activity and has more recently been observed deploying Fog ransomware. Reporting indicates overlap between Storm-0844 intrusions and ransomware incidents that leveraged VPN access, with consistent targeting of VPN software for initial access, notably Cisco ASA appliances. The actor’s operations are characterized by ransomware deployment following unauthorized access, indicating capabilities in initial access, post-exploitation, persistence, and extortion. Storm-0844 has been linked to propagation of multiple ransomware families rather than a single exclusive payload, suggesting operational flexibility in tooling and affiliate-style behavior common in the cybercrime ecosystem. High-confidence reporting specifically connects the group to Akira in earlier activity and Fog in more recent campaigns. Available information supports classification of Storm-0844 as a cybercriminal ransomware actor. Publicly available facts in this context do not establish a nation-state affiliation, specific country of origin, or a reliably defined victimology by country or industry.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distributor associated with spreading Fog ransomware and also propagating Akira.
Cluster tracked by Microsoft; overlaps with VPN-leveraging ransomware incidents. Historically associated with Akira deployments and recently observed deploying FOG ransomware, with emphasis on VPN software (notably Cisco ASA) for initial access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.