Storm
Threat Actor
Storm’s operational methodology commonly involves acquiring infostealer-sourced credentials from underground marketplaces, validating them, and then using them for authentication before deploying ransomware.
Incidents Associated with this Threat
- September 3, 2026: Star Aviation Suffers Ransomware Attack
Malware Used by this Threat Actor
No malware identified for this threat actor.
