Storm-1811

APT / StateG1046 ↗
Techniques (MITRE ATT&CK)31
SourceMITRE ATT&CK
0
Also known as:CURLY SPIDERCardinalSTAC5777

About the group

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity47
Impact: High
T1566.002T1059.001T1547.001T1033T1056T1048.002ENTRYInitial accessSpearphishing LinkEXECExecutionPowerShellPERSPersistenceRegistry Run Keys/ Startup FolderDISCDiscoverySystem Owner/UserDiscoveryCOLLCollectionInput CaptureEXFILExfiltrationExfiltration OverAsymmetric Encryp…IMPACTImpactData Encrypted forImpact

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 2989

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port193.160.32.138:18082Cobalt Strikethreatfox
ip:port132.243.172.224:80Cobalt Strikethreatfox
ip:port31.207.4.106:443Cobalt Strikethreatfox
ip:port114.215.184.158:8000Cobalt Strikethreatfox
urlhttp://69.49.229.88:443/MQEwCobalt Strikethreatfox
ip:port154.12.17.20:8080Cobalt Strikethreatfox
ip:port154.12.17.20:443Cobalt Strikethreatfox
ip:port154.12.17.20:22Cobalt Strikethreatfox
ip:port154.12.17.20:80Cobalt Strikethreatfox
ip:port129.204.55.230:443Cobalt Strikethreatfox
ip:port47.94.56.71:8080Cobalt Strikethreatfox
ip:port47.94.56.71:80Cobalt Strikethreatfox
ip:port47.94.56.71:443Cobalt Strikethreatfox
ip:port45.227.253.132:8080Cobalt Strikethreatfox
ip:port45.227.253.132:443Cobalt Strikethreatfox
ip:port45.227.253.132:80Cobalt Strikethreatfox
ip:port45.227.253.132:32775Cobalt Strikethreatfox
ip:port117.158.148.164:65535Cobalt Strikethreatfox
ip:port38.76.190.209:8888Cobalt Strikethreatfox
ip:port188.227.14.105:8080Cobalt Strikethreatfox
ip:port186.241.115.168:12443Cobalt Strikethreatfox
ip:port109.206.247.245:10881Cobalt Strikethreatfox
ip:port43.134.112.45:7500Cobalt Strikethreatfox
ip:port43.134.112.45:7000Cobalt Strikethreatfox
ip:port43.134.112.45:80Cobalt Strikethreatfox
ip:port43.134.112.45:8080Cobalt Strikethreatfox
ip:port43.134.112.45:443Cobalt Strikethreatfox
ip:port43.134.112.45:22Cobalt Strikethreatfox
ip:port101.34.208.175:18317Cobalt Strikethreatfox
md5_hashe4a34372eab0832d0682fa986a8e0b97Cobalt Strikethreatfox

+2989 indicators in total. See them all on the IOCs page.

Storm-1811 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →