Threat Intelligence / Actor / Storm-2945
Storm-2945
As of 2026-08-04, Storm-2945 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware, apt. ATT&CK coverage spans 66 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1036.005 (Match Legitimate Resource Name or Location), T1053.005 (Scheduled Task).
ATT&CK techniques observed
- T1005 Data from Local System — Collection — observed in 2 of 2 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- T1053.005 Scheduled Task — Persistence — observed in 2 of 2 tracked threats
- T1056.001 Keylogging — Credential Access — observed in 2 of 2 tracked threats
- T1059.001 PowerShell — Execution — observed in 2 of 2 tracked threats
- T1059.003 Windows Command Shell — Execution — observed in 2 of 2 tracked threats
- T1113 Screen Capture — Collection — observed in 2 of 2 tracked threats
- T1123 Audio Capture — Collection — observed in 2 of 2 tracked threats
- T1125 Video Capture — Collection — observed in 2 of 2 tracked threats
- T1204.002 User Execution: Malicious File — Execution — observed in 2 of 2 tracked threats
- T1497 Virtualization/Sandbox Evasion — Discovery — observed in 2 of 2 tracked threats
- T1528 Steal Application Access Token — Credential Access — observed in 2 of 2 tracked threats
- T1539 Steal Web Session Cookie — Credential Access — observed in 2 of 2 tracked threats
- T1543.003 Create or Modify System Process: Windows Service — Persistence — observed in 2 of 2 tracked threats
- T1547.001 Registry Run Keys / Startup Folder — Persistence — observed in 2 of 2 tracked threats
Tracked threats
- CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-Fi — HIGH
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 Tokens — HIGH
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →