Storm-0249 is an access broker distributing malware via tax-themed phishing and malicious PDFs.
Analyst brief
Storm-0249 is an access broker active since 2021, known for distributing malware such as BazaLoader, IcedID, Bumblebee, and Emotet. They primarily target organizations using tax-themed phishing emails to deliver payloads like BRc4 and Latrodectus, along with malicious PDF attachments. Their TTPs involve leveraging compromised credentials and exploiting public-facing server vulnerabilities to facilitate initial access for other actors like Storm-0501. Defenders should prioritize filtering suspicious email attachments, especially PDFs, train users against finance-themed phishing, and enforce MFA to mitigate credential theft.
Storm-0249
DEV-0249
unknown
Storm-0249 is an access broker active since 2021, known for distributing BazaLoader, IcedID, Bumblebee, and Emotet malware. The actor primarily employs phishing emails to deliver malware payloads, as evidenced by a campaign involving tax-themed emails that aimed to distribute BRc4 and Latrodectus malware. Storm-0249 has facilitated initial access for other threat actors, such as Storm-0501, by leveraging compromised credentials and exploiting known vulnerabilities in public-facing servers. Microsoft has detected malicious PDF attachments associated with Storm-0249's phishing campaigns.