Skip to main content
Mallory
1 malware family

Storm-1674

Also known asStorm-1674

Storm-1674 is a Microsoft-tracked financially motivated threat actor and access broker. Microsoft uses the Storm designation for emerging or developing clusters, and the content explicitly describes Storm-1674 as financially motivated. Since early December 2023, Microsoft observed Storm-1674 using Microsoft Teams phishing as an initial access vector, including attacker-created tenants that created meetings and sent chat messages to targets via meeting chat to bypass the accept/block screen used in other chat contexts. These lures spoofed services such as OneDrive and SharePoint and led to fake landing pages and spoofed application installs. Microsoft assessed these installs likely dropped SectopRAT or DarkGate. The actor is described as misusing the Windows ms-appinstaller URI scheme and App Installer to distribute signed malicious MSIX packages. Microsoft states Storm-1674 used malicious installers and landing page frameworks provided by Storm-1113. The content also states Storm-1674 is known for using tools based on the publicly available TeamsPhisher tool to distribute DarkGate, and that its Teams phishing campaigns have used malicious attachments such as ZIP archives containing LNK files that dropped DarkGate and Pikabot. Separate reporting in the content states Storm-1674 used Teams to deploy TeamsPhisher and other red teaming tools and injected DarkGate and other malware via Teams. Microsoft reported handoffs from Storm-1674 to ransomware operators in September 2023 that led to Black Basta ransomware deployment. The content also states Storm-1674 has used Lumma Stealer in campaigns, alongside other financially motivated actors such as Octo Tempest, Storm-1607, and Storm-1113.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics10 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.001
Domains
TA0001
Initial Access
1 technique
T1566
Phishing
TA0002
Execution
1 technique
T1204
User Execution
T1204.001
Malicious Link
T1204.002
Malicious File
TA0006
Credential Access
2 techniques
T1552
Unsecured Credentials
T1552.004
Private Keys
T1555
Credentials from Password Stores
TA0011
Command and Control
1 technique
T1105
Ingress Tool Transfer
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping7

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.