Storm-0846 is a Microsoft-tracked financially motivated cybercriminal actor associated with human-operated ransomware operations. It has been identified as a downstream ransomware operator that receives access or compromised environments from initial-access brokers rather than being described here as the actor conducting the initial intrusion itself. Observed intrusion chains involving malvertising, SEO poisoning, and abuse of the Windows App Installer ms-appinstaller/MSIX mechanism have culminated in handoffs to Storm-0846 for ransomware-stage activity. Storm-0846 is therefore linked to late-stage post-compromise operations in broader criminal intrusion ecosystems that include access brokers and malware delivery specialists. High-confidence reporting in this context supports Storm-0846’s role in ransomware deployment and post-compromise monetization, but does not provide additional corroborated detail on its malware family, victimology, geography, or distinct tradecraft beyond its participation as a ransomware operator in these handoff chains.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.