Storm-1044 is a threat actor that uses the DanaBot trojan for initial access and RDP for lateral movement to enable CACTUS ransomware.
Analyst brief
Storm-1044 (also tracked as DEV-1044) is a threat actor that gains initial access to target endpoints using the DanaBot trojan. It specifically targets select endpoints and performs lateral movement through RDP sign-in attempts before handing control to the collaborating group Twisted Spider. Their key TTPs involve deploying DanaBot, using RDP for network propagation, and enabling the delivery of CACTUS ransomware by Twisted Spider. Defenders should monitor for anomalous RDP activity, DanaBot-related IoCs, and be vigilant against malvertising campaigns that lead to these attacks.
Storm-1044
DEV-1044
unknown
Storm-1044 has been identified as part of a cyber campaign in collaboration with Twisted Spider. They employ a strategic approach, targeting specific endpoints using an initial access trojan called DanaBot. Once they gain access, Storm-1044 initiates lateral movement through Remote Desktop Protocol sign-in attempts, passing control to Twisted Spider. Twisted Spider then compromises the endpoints by introducing the CACTUS ransomware. Microsoft has detected ongoing malvertising attacks involving Storm-1044, leading to the deployment of CACTUS ransomware.