← Back to Actors
Storm-1811
Storm-1811
[Storm-1811](https://attack.mitre.org/groups/G1046) is a financially-motivated entity linked to [Black Basta](https://attack.mitre.org/software/S1070) ransomware deployment. [Storm-1811](https://attack.mitre.org/groups/G1046) is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.(Citation: Microsoft Storm-1811 2024)(Citation: rapid7-email-bombing)(Citation: RedCanary Storm-1811 2024)(Citation: RedC...
32
Techniques
26
Covered
6
Gaps
81%
Coverage
Coverage26/32
GAPS (6)
COVERED (26)
T1021.002SMB/Windows Admin Shares74 det.T1021.004SSH35 det.T1027.013Encrypted/Encoded File8 det.T1033System Owner/User Discovery62 det.T1036Masquerading616 det.T1036.005Match Legitimate Resource Name or Location45 det.T1056Input Capture7 det.T1059.001PowerShell376 det.T1059.003Windows Command Shell87 det.T1074.001Local Data Staging10 det.T1087.002Domain Account58 det.T1105Ingress Tool Transfer191 det.T1140Deobfuscate/Decode Files or Information58 det.T1204.002Malicious File461 det.T1219.002Remote Desktop Software53 det.T1222.001Windows Permissions23 det.T1482Domain Trust Discovery41 det.T1486Data Encrypted for Impact394 det.T1547.001Registry Run Keys / Startup Folder53 det.T1566.002Spearphishing Link1086 det.T1566.003Spearphishing via Service102 det.T1570Lateral Tool Transfer23 det.T1574.001DLL111 det.T1583.001Domains68 det.T1588.002Tool13 det.T1656Impersonation253 det.