About the group
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 31
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Known infrastructure 2989
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
193.160.32.138:18082Cobalt Strikethreatfox132.243.172.224:80Cobalt Strikethreatfox31.207.4.106:443Cobalt Strikethreatfox114.215.184.158:8000Cobalt Strikethreatfoxhttp://69.49.229.88:443/MQEwCobalt Strikethreatfox154.12.17.20:8080Cobalt Strikethreatfox154.12.17.20:443Cobalt Strikethreatfox154.12.17.20:22Cobalt Strikethreatfox154.12.17.20:80Cobalt Strikethreatfox129.204.55.230:443Cobalt Strikethreatfox47.94.56.71:8080Cobalt Strikethreatfox47.94.56.71:80Cobalt Strikethreatfox47.94.56.71:443Cobalt Strikethreatfox45.227.253.132:8080Cobalt Strikethreatfox45.227.253.132:443Cobalt Strikethreatfox45.227.253.132:80Cobalt Strikethreatfox45.227.253.132:32775Cobalt Strikethreatfox117.158.148.164:65535Cobalt Strikethreatfox38.76.190.209:8888Cobalt Strikethreatfox188.227.14.105:8080Cobalt Strikethreatfox186.241.115.168:12443Cobalt Strikethreatfox109.206.247.245:10881Cobalt Strikethreatfox43.134.112.45:7500Cobalt Strikethreatfox43.134.112.45:7000Cobalt Strikethreatfox43.134.112.45:80Cobalt Strikethreatfox43.134.112.45:8080Cobalt Strikethreatfox43.134.112.45:443Cobalt Strikethreatfox43.134.112.45:22Cobalt Strikethreatfox101.34.208.175:18317Cobalt Strikethreatfoxe4a34372eab0832d0682fa986a8e0b97Cobalt Strikethreatfox+2989 indicators in total. See them all on the IOCs page.
References
Storm-1811 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →