Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-03

Storm-1811

Also known as:STAC5777

As of 2026-06-10, Storm-1811 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning ransomware, malware. Also known as STAC5777. ATT&CK coverage spans 56 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1071 (Application Layer Protocol), T1087 (Account Discovery).

Tracked threats
33 high
First seen
2026-03-17
Last seen
2026-06-10
ATT&CK techniques
56across 3 of 3 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 3 tracked threat(s) · Categories: RANSOMWARE, MALWARE

Activity timeline

Storm-1811 appears in 3 tracked threats between and ; the busiest month was 2026-03 with 1 report.

ATT&CK techniques observed

56 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (9), Discovery (8), Command and Control (7), Exfiltration (4), Resource Development (4), Collection (3)
  • T1059 Command and Scripting Interpreter — Executionobserved in 3 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 3 of 3 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1204 User Execution — Executionobserved in 3 of 3 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 3 of 3 tracked threats
  • T1547 Boot or Logon Autostart Execution — Persistenceobserved in 3 of 3 tracked threats
  • T1566 Phishing — Initial Accessobserved in 3 of 3 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 3 of 3 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 2 of 3 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1048 Exfiltration Over Alternative Protocol — Exfiltrationobserved in 2 of 3 tracked threats
  • T1056 Input Capture — Credential Accessobserved in 2 of 3 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1482 Domain Trust Discovery — Discoveryobserved in 2 of 3 tracked threats

Tracked threats