G1046: Storm-1811
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]
Security context for executives and security teams
G1046: Storm-1811 describes [Storm-1811](https://attack.mitre.org/groups/G1046) is a financially-motivated entity linked to [Black Basta](https://attack.mitre.org/software/S1070) ransomware deployment. [Storm-1811](https://attack.mitre.org/groups/G1046) is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.(Citation: Microsoft Storm-1811 2024)(Cit...
Executive priority
G1046: Storm-1811 is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1046: Storm-1811 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1046: Storm-1811 appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Storm-1811
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1585.003 | Cloud AccountsSub-technique | Storm-1811 has created malicious accounts to enable activity via Microsoft Teams, typically spoofing various IT support and helpdesk themes.[1] |
| Enterprise | T1074.001 | Local Data StagingSub-technique | Storm-1811 has locally staged captured credentials for subsequent manual exfiltration.[2] |
| Enterprise | T1667 | Email Bombing | Storm-1811 has deployed large volumes of non-malicious email spam to victims in order to prompt follow-on interactions with the threat actor posing as IT support or helpdesk to resolve the problem.[2][3] |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices.[2] |
| Enterprise | T1583.001 | DomainsSub-technique | Storm-1811 has created domains for use with RMM tools.[2] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package.[2] |
| Enterprise | T1588.002 | ToolSub-technique | Storm-1811 acquired various legitimate and malicious tools, such as RMM software and commodity malware packages, for operations.[1][2] |
| Enterprise | T1219.002 | Remote Desktop SoftwareSub-technique | Storm-1811 has abused multiple types of legitimate remote access software and tools, such as ScreenConnect, NetSupport Manager, and AnyDesk.[1][2] |
| Enterprise | T1059.001 | PowerShellSub-technique | Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server.[2] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines.[1][2] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | Storm-1811 has distributed password-protected archives such as ZIP files during intrusions.[2] |
| Enterprise | T1036.010 | Masquerade Account NameSub-technique | Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing.[1] |
| Enterprise | T1056 | Input Capture | Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item.[2] |
| Enterprise | T1574.001 | DLLSub-technique | Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload.[2] |
| Enterprise | T1204.002 | Malicious FileSub-technique | Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity.[1][2][3] |
| Enterprise | T1566.004 | Spearphishing VoiceSub-technique | Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access.[1][2][3] |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process.[2] |
| Enterprise | T1684.001 | ImpersonationSub-technique | Storm-1811 impersonates help desk and IT support personnel for phishing and social engineering purposes during initial access to victim environments.[1] |
| Enterprise | T1105 | Ingress Tool Transfer | Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.[1][2][4] |
| Enterprise | T1570 | Lateral Tool Transfer | Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks.[2] |
| Enterprise | T1021.004 | SSHSub-technique | Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access.[1] |
| Enterprise | T1486 | Data Encrypted for Impact | Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments.[1] |
| Enterprise | T1036 | Masquerading | Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations.[2] |
| Enterprise | T1482 | Domain Trust Discovery | Storm-1811 has enumerated domain accounts and access during intrusions.[1] |
| Enterprise | T1566.003 | Spearphishing via ServiceSub-technique | Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel.[1] |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | Storm-1811 has distributed malicious links to victims that redirect to EvilProxy-based phishing sites to harvest credentials.[1] |
| Enterprise | T1087.002 | Domain AccountSub-technique | Storm-1811 has performed domain account enumeration during intrusions.[1] |
| Enterprise | T1033 | System Owner/User Discovery | Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator.[2] |
| Enterprise | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolSub-technique | Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP).[2] |
| Enterprise | T1222.001 | Windows PermissionsSub-technique | Storm-1811 has used `cacls.exe` via batch script to modify file and directory permissions in victim environments.[2] |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket.[2] |
Groups, software, and campaigns
S1070: Black Basta
Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.[1][2][3][4][5][6]
S0154: Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]
S1209: Quick Assist
Quick Assist is a remote assistance tool primarily for Microsoft Windows, although a macOS version also exists. Quick Assist allows for remote screen sharing and, with end user approval, remote control and command execution on the enabling device.[1][2]
S0190: BITSAdmin
S0029: PsExec
S0357: Impacket
S0650: QakBot
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | b540524c048d… | ||
| 19.1 | 1.0 | Older bundle | 29fa4e2a8110… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Microsoft Storm-1811 2024
Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.
Open source URL - [2]rapid7-email-bombing
Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.
Open source URL - [3]RedCanary Storm-1811 2024
Red Canary Intelligence. (2024, December 2). Storm-1811 exploits RMM tools to drop Black Basta ransomware. Retrieved March 14, 2025.
Open source URL - [4]RedCanary June Insights 2024
The Red Canary Team. (2024, June 20). Intelligence Insights: June 2024. Retrieved March 14, 2025.
Open source URL - [5]mitre-attackG1046Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
