# Storm-1811

> As of 2026-06-10, Storm-1811 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning ransomware, malware. Also known as STAC5777. ATT&CK coverage spans 56 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1071 (Application Layer Protocol), T1087 (Account Discovery).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** RANSOMWARE, MALWARE
- **Also known as:** STAC5777
- **As of:** 2026-06-10

## ATT&CK techniques observed

56 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (9), Discovery (8), Command and Control (7), Exfiltration (4), Resource Development (4), Collection (3).

- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 3 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 3 of 3 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 3 of 3 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 3 of 3 tracked threats
- [T1547](https://intel.threadlinqs.com/technique/T1547) Boot or Logon Autostart Execution — Persistence — observed in 3 of 3 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 3 of 3 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 3 of 3 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 2 of 3 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1048](https://intel.threadlinqs.com/technique/T1048) Exfiltration Over Alternative Protocol — Exfiltration — observed in 2 of 3 tracked threats
- [T1056](https://intel.threadlinqs.com/technique/T1056) Input Capture — Credential Access — observed in 2 of 3 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1482](https://intel.threadlinqs.com/technique/T1482) Domain Trust Discovery — Discovery — observed in 2 of 3 tracked threats

## Tracked threats

- [Capita Black Basta Ransomware Incident (March 2023) — Record £14M UK ICO Fine for 6M+ Affected Individuals](https://intel.threadlinqs.com/threat/TL-2026-0767) — HIGH
- [Nimbus RAT: Java-based Remote Access Trojan Delivered via Microsoft Teams Vishing, Quick Assist, and Google Drive C2](https://intel.threadlinqs.com/threat/TL-2026-0847) — HIGH
- [A0Backdoor via Microsoft Teams Social Engineering — Storm-1811/STAC5777 DNS MX C2 Covert Channel](https://intel.threadlinqs.com/threat/TL-2026-0243) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Storm-1811
