Storm Worm is a trojan/botnet malware family associated with a large zombie-computer network used for spam and phishing operations. The provided content describes Storm Worm as a shape-shifting threat capable of lying dormant for weeks and reappearing in new forms, with delivery observed via malicious URLs, ZIP attachments, MP3 attachments, and digital greeting cards, including seasonal lures such as Christmas- and New Year's-themed messages. Fortinet reported two phishing campaigns against major banks using the Storm Worm botnet, described as the first known use of Storm infrastructure against the financial sector. In those campaigns, attackers impersonated Barclays and later Halifax Bank, sending thousands of broad phishing emails that redirected victims to fraudulent banking sites to steal login names and passwords; one fake i-Barclays site was hosted on a Russia-registered domain. Fortinet assessed the operators used outdated phishing kits and may have been relatively unskilled, while Cisco had warned that the Storm botnet infrastructure might be rented or sub-let to cybercriminals for phishing. The content also notes that Waledac was widely regarded by experts as a successor to the botnet created by Storm Worm. Infrastructure associated with Storm Worm was reportedly found on Atrivo/Intercage/Cernel/Hostfresh systems, including references to a Storm Worm installer and controller. High-confidence indicators in the provided material are limited to behavioral and infrastructure references rather than specific hashes or domains, aside from the bogus i-Barclays phishing site and the mention of Russia-registered hosting used in that campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Severa rented out segments of his Waledac botnet to anyone seeking a vehicle for sending spam. For $200, vetted users could hire his botnet to blast one million emails containing malware or ads for male enhancement drugs.
Last week, researchers at SecureWorks discovered that the Storm worm authors have taken their full attention off of e-mail-based attacks and have started creating malicious Web pages.
With students returning to campus in the next few weeks, schools are expected to scan the servers on their network to find vulnerabilities and malware that the students are bringing back with them. When the scanner hits an infected computer that is part of the Storm botnet, the rest of the botnet directs a DDoS attack back against the computer running the scan.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm/botnet malware family referenced here as being hosted via Atrivo/Intercage infrastructure, specifically including installer and controller components.
A botnet/trojan used to distribute phishing emails and support phishing attacks. The content describes it as a shape-shifting malware family delivered via URLs, ZIP or MP3 attachments, and digital greeting cards, with infected machines sending themed lure messages.
Earlier worm/botnet referenced only as the predecessor whose botnet Waledac reportedly replaced.
Named malware referenced via the archived article title, indicating discussion of the Storm Worm botnet being offered for sale.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.