Storm-0861 is an Iran-linked threat cluster assessed to be associated with the Ministry of Intelligence and Security (MOIS). It has been publicly linked to operations targeting government and telecommunications organizations in the Middle East and is notable for activity patterns in which it gains and maintains access well in advance of follow-on operations by other Iranian actors. Reporting has described Storm-0861 as part of a broader ecosystem of MOIS-affiliated intrusion sets whose tradecraft overlaps with clusters such as UNC1860, Shrouded Snooper, Scarred Manticore, and APT34. The actor’s role has been characterized primarily as enabling access and persistence rather than public-facing extortion or ransomware operations. Observed behavior includes compromising internet-facing systems, maintaining long-term footholds, and supporting subsequent destructive or disruptive activity by partner clusters. A recurring pattern attributed to MOIS-linked operations describes Storm-0861 obtaining access months before another MOIS-linked cluster, Storm-0842, deploys wiper malware. This handoff pattern has been reported in operations affecting Albania in 2022 and Israel in late 2023. Storm-0861 has been associated with targeting in the telecommunications and government sectors across the Middle East. Its operational profile aligns with espionage-oriented state activity focused on pre-positioning, persistence, and support to downstream network attack objectives. High-confidence public reporting ties the cluster to Iranian state interests, but detailed malware family attribution specific to Storm-0861 remains limited in the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked threat actor cluster listed in Microsoft's naming taxonomy mapping.
MOIS-linked actor assessed to perform initial access/pre-positioning, enabling later destructive operations by another MOIS-linked group (Storm-0842), observed in both Albania (2022) and Israel (Oct, during war) using a similar handoff playbook.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.