Storm-1674
Storm-1674 is a Microsoft-tracked financially motivated threat actor and access broker. Microsoft uses the Storm designation for emerging or developing clusters, and the content explicitly describes Storm-1674 as financially motivated. Since early December 2023, Microsoft observed Storm-1674 using Microsoft Teams phishing as an initial access vector, including attacker-created tenants that created meetings and sent chat messages to targets via meeting chat to bypass the accept/block screen used in other chat contexts. These lures spoofed services such as OneDrive and SharePoint and led to fake landing pages and spoofed application installs. Microsoft assessed these installs likely dropped SectopRAT or DarkGate. The actor is described as misusing the Windows ms-appinstaller URI scheme and App Installer to distribute signed malicious MSIX packages. Microsoft states Storm-1674 used malicious installers and landing page frameworks provided by Storm-1113. The content also states Storm-1674 is known for using tools based on the publicly available TeamsPhisher tool to distribute DarkGate, and that its Teams phishing campaigns have used malicious attachments such as ZIP archives containing LNK files that dropped DarkGate and Pikabot. Separate reporting in the content states Storm-1674 used Teams to deploy TeamsPhisher and other red teaming tools and injected DarkGate and other malware via Teams. Microsoft reported handoffs from Storm-1674 to ransomware operators in September 2023 that led to Black Basta ransomware deployment. The content also states Storm-1674 has used Lumma Stealer in campaigns, alongside other financially motivated actors such as Octo Tempest, Storm-1607, and Storm-1113.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Microsoft-tracked activity cluster described as a ransomware group that has used LummaStealer in campaigns.
Storm-1674 is an initial access broker leveraging Microsoft Teams to deploy phishing tools and malware, facilitating access for further cybercriminal activity.
Financially motivated threat actor cluster tracked by Microsoft.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.