LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1046: Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]

EnterpriseG1046GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1046: Storm-1811 describes [Storm-1811](https://attack.mitre.org/groups/G1046) is a financially-motivated entity linked to [Black Basta](https://attack.mitre.org/software/S1070) ransomware deployment. [Storm-1811](https://attack.mitre.org/groups/G1046) is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.(Citation: Microsoft Storm-1811 2024)(Cit...

Executive priority

G1046: Storm-1811 is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1046: Storm-1811 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1046: Storm-1811 appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

31 rows
DomainIDNameRelationship / procedure
EnterpriseT1585.003Cloud AccountsSub-technique

Storm-1811 has created malicious accounts to enable activity via Microsoft Teams, typically spoofing various IT support and helpdesk themes.[1]

EnterpriseT1074.001Local Data StagingSub-technique

Storm-1811 has locally staged captured credentials for subsequent manual exfiltration.[2]

EnterpriseT1667Email Bombing

Storm-1811 has deployed large volumes of non-malicious email spam to victims in order to prompt follow-on interactions with the threat actor posing as IT support or helpdesk to resolve the problem.[2][3]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices.[2]

EnterpriseT1583.001DomainsSub-technique

Storm-1811 has created domains for use with RMM tools.[2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package.[2]

EnterpriseT1588.002ToolSub-technique

Storm-1811 acquired various legitimate and malicious tools, such as RMM software and commodity malware packages, for operations.[1][2]

EnterpriseT1219.002Remote Desktop SoftwareSub-technique

Storm-1811 has abused multiple types of legitimate remote access software and tools, such as ScreenConnect, NetSupport Manager, and AnyDesk.[1][2]

EnterpriseT1059.001PowerShellSub-technique

Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines.[1][2]

EnterpriseT1140Deobfuscate/Decode Files or Information

Storm-1811 has distributed password-protected archives such as ZIP files during intrusions.[2]

EnterpriseT1036.010Masquerade Account NameSub-technique

Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing.[1]

EnterpriseT1056Input Capture

Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item.[2]

EnterpriseT1574.001DLLSub-technique

Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload.[2]

EnterpriseT1204.002Malicious FileSub-technique

Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity.[1][2][3]

EnterpriseT1566.004Spearphishing VoiceSub-technique

Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access.[1][2][3]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process.[2]

EnterpriseT1684.001ImpersonationSub-technique

Storm-1811 impersonates help desk and IT support personnel for phishing and social engineering purposes during initial access to victim environments.[1]

EnterpriseT1105Ingress Tool Transfer

Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.[1][2][4]

EnterpriseT1570Lateral Tool Transfer

Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks.[2]

EnterpriseT1021.004SSHSub-technique

Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access.[1]

EnterpriseT1486Data Encrypted for Impact

Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments.[1]

EnterpriseT1036Masquerading

Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations.[2]

EnterpriseT1482Domain Trust Discovery

Storm-1811 has enumerated domain accounts and access during intrusions.[1]

EnterpriseT1566.003Spearphishing via ServiceSub-technique

Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel.[1]

EnterpriseT1566.002Spearphishing LinkSub-technique

Storm-1811 has distributed malicious links to victims that redirect to EvilProxy-based phishing sites to harvest credentials.[1]

EnterpriseT1087.002Domain AccountSub-technique

Storm-1811 has performed domain account enumeration during intrusions.[1]

EnterpriseT1033System Owner/User Discovery

Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator.[2]

EnterpriseT1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolSub-technique

Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP).[2]

EnterpriseT1222.001Windows PermissionsSub-technique

Storm-1811 has used `cacls.exe` via batch script to modify file and directory permissions in victim environments.[2]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket.[2]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S1070: Black Basta

Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.[1][2][3][4][5][6]

WindowsESXi
MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
ToolEnterprise

S1209: Quick Assist

Quick Assist is a remote assistance tool primarily for Microsoft Windows, although a macOS version also exists. Quick Assist allows for remote screen sharing and, with end user approval, remote control and command execution on the enabling device.[1][2]

WindowsmacOS
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S0357: Impacket

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.[1]

LinuxmacOSWindows
MalwareEnterprise

S0650: QakBot

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.0
Created
Modified
Raw hash
b540524c048d4704...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.0Current bundleb540524c048d…
19.11.0Older bundle29fa4e2a8110…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Microsoft Storm-1811 2024

    Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.

    Open source URL
  2. [2]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  3. [3]
    RedCanary Storm-1811 2024

    Red Canary Intelligence. (2024, December 2). Storm-1811 exploits RMM tools to drop Black Basta ransomware. Retrieved March 14, 2025.

    Open source URL
  4. [4]
    RedCanary June Insights 2024

    The Red Canary Team. (2024, June 20). Intelligence Insights: June 2024. Retrieved March 14, 2025.

    Open source URL
  5. [5]
    mitre-attackG1046
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.