Access broker that uses TeamsPhisher tools to distribute DarkGate and Pikabot malware for ransomware handoffs.
Analyst brief
Storm-1674 is an access broker that leverages tools based on the publicly available TeamsPhisher utility to distribute DarkGate and Pikabot malware. The actor predominantly targets users through phishing lures delivered over Microsoft Teams, often using malicious attachments like ZIP files containing LNK files to initiate the DarkGate infection chain. Defenders should closely monitor Teams-based phishing attempts and investigate suspicious LNK execution, as handoffs from Storm-1674 have led to Black Basta ransomware deployments.
Storm-1674
unknown
Storm-1674 is an access broker known for using tools based on the publicly available TeamsPhisher tool to distribute DarkGate malware. Storm-1674 campaigns have typically relied on phishing lures sent over Teams with malicious attachments, such as ZIP files containing a LNK file that ultimately drops DarkGate and Pikabot. In September 2023, Microsoft observed handoffs from Storm-1674 to ransomware operators that have led to Black Basta ransomware deployment.