STAC5143 is a previously unreported threat cluster tracked by Sophos. Sophos described it as copying the Storm-1811 playbook and assessed with medium confidence that it may have connections to FIN7, also known as Sangria Tempest or Carbon Spider, based on tooling and obfuscation similarities; this attribution is not definitive. Sophos investigated STAC5143 activity in late 2024 as part of ransomware and data-theft extortion operations that abused Microsoft Office 365 and the default ability for external Microsoft Teams users to contact internal staff. The observed intrusion pattern included email bombing, fake IT support contact over Teams, persuading victims to grant remote access through Teams screen control, malware deployment, command-and-control activity, and attempted data theft or ransomware-related objectives. In one incident, the actor used Teams remote screen control to open a command shell and deploy files from an external SharePoint file store. STAC5143 deployed Java archive files, a Java runtime, and Python components; executed MailQueue-Handler.jar via javaw.exe; used WMIC, PowerShell with ExecutionPolicy Bypass, and likely encoded commands; downloaded 7zip components; and extracted a ProtonVPN executable with a malicious sideloaded nethost.dll. It conducted discovery with whoami.exe, net user /domain, nltest.exe, ping.exe, and ipconfig.exe. A second-stage Java payload executed identity.jar and extracted winter.zip into C:\ProgramData, after which a bundled Python interpreter renamed to debug.exe launched Python backdoor scripts. Two Python components, 166_65.py and 45_237_80.py, were copies of the RPivot reverse SOCKS proxy, and another script, 37_44.py, was an RPivot component used to connect to a Tor relay. Known aliases mentioned in the content for the possible linked actor are FIN7, Sangria Tempest, and Carbon Spider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously unreported threat cluster using email bombing, fake Microsoft Teams tech-support social engineering, Teams remote control, Java/JAR-based staging, and Python backdoors to gain access, conduct discovery, establish command and control, and support data theft and ransomware/extortion activity.
Previously unreported threat cluster using email bombing and fake Microsoft Teams tech-support social engineering to gain remote access, deploy Java and Python-based backdoors, conduct discovery, and support data theft and ransomware/extortion activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.