Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1046
MITRE ATT&CK Group

Storm-1811 (G1046)

ShareXLinkedInRedditHN

[Storm-1811](https://attack.mitre.org/groups/G1046) is a financially-motivated entity linked to [Black Basta](https://attack.mitre.org/software/S1070) ransomware deployment. [Storm-1811](https://attack.mitre.org/groups/G1046) is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.(Citation: Microsoft Storm-1811 2024)(Citation: rapid7-email-bombing)(Citation: RedCanary Storm-1811 2024)(Citation: RedCanary June Insights 2024)

▪Techniques used (31)

T1585.003Cloud AccountsT1074.001Local Data StagingT1667Email BombingT1547.001Registry Run Keys / Startup FolderT1583.001DomainsT1036.005Match Legitimate Resource Name or LocationT1588.002ToolT1219.002Remote Desktop SoftwareT1059.001PowerShellT1059.003Windows Command ShellT1140Deobfuscate/Decode Files or InformationT1036.010Masquerade Account NameT1056Input CaptureT1574.001DLLT1204.002Malicious FileT1566.004Spearphishing VoiceT1027.013Encrypted/Encoded FileT1684.001ImpersonationT1105Ingress Tool TransferT1570Lateral Tool TransferT1021.004SSHT1486Data Encrypted for ImpactT1036MasqueradingT1482Domain Trust DiscoveryT1566.003Spearphishing via ServiceT1566.002Spearphishing LinkT1087.002Domain AccountT1033System Owner/User DiscoveryT1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolT1222.001Windows PermissionsT1021.002SMB/Windows Admin Shares

▪Software used (7)

S1070Black BastamalwareS0154Cobalt StrikemalwareS1209Quick AssisttoolS0190BITSAdmintoolS0029PsExectoolS0357ImpackettoolS0650QakBotmalware
G1046on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.