Skip to content
skopnix
← adversaries
Unknown

Storm-1113

APOTHECARY SPIDER
misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

Storm-1113 is a threat actor that acts both as an access broker focused on malware distribution through search advertisements and as an “as-a-service” entity providing malicious installers and landing page frameworks. In Storm-1113 malware distribution campaigns, users are directed to landing pages mimicking well-known software that host installers, often MSI files, that lead to the installation of malicious payloads. Storm-1113 is also the developer of EugenLoader, a commodity malware first observed around November 2022.

Take it with you
References
Early access

Track Storm-1113 on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected