Storm-0249 is a financially motivated cybercriminal threat actor tracked as an initial access broker active since at least 2021. The actor is known for obtaining and brokering access to victim environments for downstream ransomware and other criminal operations, and has been linked to campaigns distributing malware including BazaLoader, IcedID, Bumblebee, Emotet, Brute Ratel C4, and Latrodectus. Storm-0249 has evolved from broad phishing activity into more targeted and stealthy intrusion operations aligned with the cybercrime-as-a-service ecosystem. The actor has used multiple initial access vectors over time. Earlier activity relied heavily on large-scale phishing, including tax-themed lures and credential-harvesting infrastructure. More recent operations shifted toward compromised legitimate websites, malvertising, SEO poisoning, and ClickFix-style social engineering that tricks users into executing malicious commands. Storm-0249 has been specifically associated with ClickFix campaigns delivering Latrodectus and other initial access malware, including activity involving compromised websites and likely exploitation of WordPress vulnerabilities. Post-compromise, Storm-0249 has been observed abusing trusted Windows utilities and endpoint detection and response software to evade detection, establish persistence, and prepare victim networks for ransomware deployment. Reported tradecraft includes fileless PowerShell execution, use of built-in Windows tools such as curl, DLL sideloading, and abuse of legitimate signed EDR components, particularly SentinelOne-related binaries, to load malicious code under the cover of trusted processes. This activity supports reconnaissance, command-and-control, persistence, and staging of ransomware-ready access for sale or handoff to ransomware operators. Storm-0249 has also been linked to use of malware signed through the Fox Tempest malware-signing-as-a-service operation, which provided fraudulently trusted code-signing certificates to cybercriminal customers. The actor has been identified among Fox Tempest customers alongside other ransomware-linked groups, underscoring its role as an enabler and supplier of access within the broader financially motivated intrusion ecosystem rather than as a purely standalone malware operator. Storm-0249 is best characterized as a stealth-focused access broker supporting ransomware intrusion chains through phishing, social engineering, malware delivery, defense evasion, persistence, and post-exploitation tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named by Microsoft as a threat group that utilized malware signed through Fox Tempest's fraudulent signing service.
Named as a customer of Fox Tempest's malware-signing service.
Named as a threat actor linked to the Fox Tempest malware-signing service.
Named activity cluster observed using Fox Tempest-signed malware in real-world intrusions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.