Blitz Brigantine, also tracked as Storm-1811 and STAC5777, is a financially motivated threat cluster linked in the provided reporting to Black Basta ransomware operations and described as a Black Basta and Cactus ransomware affiliate. Reporting attributes to this actor a social-engineering intrusion playbook active since at least August 2025 through late February 2026, with overlap to activity reported in late 2024 and 2025. The group primarily targets finance and healthcare organizations, with reporting citing victims across 10 countries including the United States, United Kingdom, Germany, Canada, Australia, France, Japan, South Korea, Singapore, and Switzerland. The intrusion chain uses email bombing, Microsoft Teams help-desk impersonation, and Quick Assist social engineering to obtain remote access. After access is granted, the operators deploy digitally signed MSI installers masquerading as Microsoft software, including Teams-related and CrossDeviceService/Phone Link themed packages, sometimes hosted on Microsoft personal cloud storage. Post-access tooling in the cited campaign used DLL sideloading with legitimate Microsoft-signed executables and attacker-signed DLLs including hostfxr.dll, domain_actions.dll, spoofed zlib1.dll, spoofed sqlite3.dll, and in some cases clipsp.dll. The malicious loader decrypts and launches a payload BlueVoyant named A0Backdoor. Reported anti-analysis features include junk functions, excessive thread creation, runtime decryption, environmental keying, a roughly 55-hour execution window, hidden command-line character requirements, QEMU and sandbox checks, and debugger checks. A0Backdoor is described as memory-resident, fingerprinting hosts via Windows APIs such as DeviceIoControl, GetUserNameExW, and GetComputerNameW, and using covert DNS tunneling for command and control via MX queries through trusted public resolvers such as 1.1.1.1 and 8.8.8.8. Reporting also associates the campaign with the domain fsdgh[.]com. The provided content describes this activity as an evolution or tactical shift toward more customized, stealth-focused intrusions that can support reconnaissance, lateral movement, and eventual ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware affiliate activity using the A0Backdoor family as a precursor for intrusion, persistence, reconnaissance, lateral movement, and eventual Black Basta or Cactus ransomware deployment. The campaign uses Teams vishing, Quick Assist abuse, trojanized MSI installers, DLL sideloading, and DNS MX tunneling for covert C2.
Social-engineering-led initial access (Microsoft Teams impersonation / fake internal IT support) followed by deployment of malicious MSI installers and DLL sideloading to load a multi-stage payload culminating in A0Backdoor; historically linked in the article to follow-on ransomware operations.
Conducting social-engineering intrusions against finance and healthcare employees by impersonating internal IT support, using email bombing and Microsoft Teams to obtain Quick Assist remote access, then deploying a stealthy loader and A0Backdoor for persistence and information theft.
Financially motivated intrusion cluster using Microsoft Teams impersonation and Windows Quick Assist social engineering to gain remote access, then deploying signed MSI-based loaders/backdoors and (in prior documented chains) follow-on tooling leading to ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.