Storm-1000 is a cybercrime threat actor associated with a large-scale malvertising operation observed from early December 2024 that delivered information-stealing malware, including Lumma Stealer, through GitHub-hosted droppers. The actor used scam and pirated streaming websites with embedded redirects to funnel victims to malicious repositories hosting signed payloads. These payloads functioned as droppers for additional Windows malware, performed host discovery, and exfiltrated collected system information over HTTP using encoded parameters. Some infection chains also deployed NetSupport RAT and established persistence through registry modification. The operation demonstrated rapid infrastructure regeneration and broad reach, with malicious repositories repeatedly recreated after takedowns and victim impact observed across nearly one million devices worldwide spanning multiple industries and organization sizes. Analysis also identified overlap with the Doenerium malware family, including shared binary characteristics and operational links to infrastructure historically associated with Lumma Stealer. Storm-1000’s observed tradecraft supports classification as a financially motivated cybercrime actor focused on initial access through malvertising, payload delivery via trusted platforms, host reconnaissance, information theft, persistence, and data exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.