Storm-0494 is a financially motivated threat actor facilitating Gootloader infections targeting the US health sector.
Analyst brief
Storm-0494 is a financially motivated threat actor that facilitates Gootloader infections, primarily targeting the U.S. health sector. It collaborates with groups like Vice Society and uses tools such as the Supper backdoor, AnyDesk, and MEGA for initial access and persistence. Key TTPs include lateral movement via RDP and deployment of INC ransomware through the WMI Provider Host. Defenders should focus on detecting Gootloader delivery methods, anomalous RDP activity, and ransomware deployment via WMI to mitigate this threat.
Storm-0494
unknown
Storm-0494 is a threat actor that facilitates Gootloader infections, which are then exploited by groups like Vice Society to deploy tools such as the Supper backdoor, AnyDesk, and MEGA. They utilize RDP for lateral movement and employ the WMI Provider Host to deploy the INC ransomware payload. Microsoft has identified their activities as part of a campaign targeting the U.S. health sector. Their operations are characterized by financially motivated tactics.