Threat Intelligence / Actor / Storm-2945

Storm-2945

As of 2026-08-04, Storm-2945 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware, apt. ATT&CK coverage spans 66 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1036.005 (Match Legitimate Resource Name or Location), T1053.005 (Scheduled Task).

Nation: Russia · 2 tracked threat(s) · Categories: MALWARE, APT

ATT&CK techniques observed

66 techniques observed across 2 of 2 tracked threats · Credential Access (9), Stealth (formerly Defense Evasion) (8), Collection (7), Discovery (7), Initial Access (6), Resource Development (6)

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence