Storm-0978

Threat Actor updated 5 months ago (2024-05-04T19:29:47.342Z)
Download STIX
Preview STIX
Storm-0978, also known as RomCom or DEV-0978, is a threat actor group alleged to have connections with Russia. Microsoft, in a blog post published on July 11, 2023, accused this group of exploiting the vulnerability CVE-2023-36884 to install backdoors on target systems. The cybersecurity industry has identified Storm-0978 as a significant entity executing actions with malicious intent, possibly backed by a government entity. The group's activities primarily revolve around a phishing campaign that targets defense and government entities across Europe and North America. They employ bait related to the Ukrainian World Congress, a non-profit organization representing all Ukrainian public organizations in diaspora, to lure their targets. This sophisticated approach suggests financial and espionage motives behind their operations. For individuals with experience in cybersecurity, it is strongly recommended to carefully review the Threat Intelligence post about Storm-0978. Understanding the tactics, techniques, and procedures (TTPs) of such threat actors is crucial in developing robust defenses and effective countermeasures. Awareness and preparedness remain key elements in combating these evolving cyber threats.
Description last updated: 2023-11-13T13:31:43.707Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The RomCom Malware is associated with Storm-0978. The RomCom malware, a malicious software that has been active since 2022, is an ongoing cyber threat. This Remote Access Trojan (RAT) is known for its various harmful activities including ransomware attacks, extortion, and targeted credential gathering, primarily aimed at supporting intelligence-gatis related to
2
Source Document References
Information about the Storm-0978 Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more