Storm-1084 is a threat actor that has been observed collaborating with the MuddyWater group. They have used the DarkBit persona to mask their involvement in targeted attacks. Storm-1084 has been linked to destructive actions, including the encryption of on-premise devices and deletion of cloud resources. They have been observed using tools such as Rport, Ligolo, and a customized PowerShell backdoor. The extent of their autonomy or collaboration with other Iranian threat actors is currently unclear.
What destructive operations does the Storm-1084 group typically carry out during its attacks?+
The Storm-1084 group conducts destructive operations during targeted attacks, including encrypting on-premise devices and deleting cloud resources.
Which tools should defenders monitor to detect Storm-1084's lateral movement activity?+
Defenders should monitor for lateral movement tools used by Storm-1084, specifically Ligolo and Rport, and focus on detecting anomalous PowerShell execution.