# Storm-2945

> As of 2026-08-04, Storm-2945 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware, apt. ATT&CK coverage spans 66 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1036.005 (Match Legitimate Resource Name or Location), T1053.005 (Scheduled Task).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** MALWARE, APT
- **As of:** 2026-08-04

## ATT&CK techniques observed

66 techniques observed across 2 of 2 tracked threats. Tactics: Credential Access (9), Stealth (formerly Defense Evasion) (8), Collection (7), Discovery (7), Initial Access (6), Resource Development (6).

- [T1005](https://attack.mitre.org/techniques/T1005/) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1036.005](https://attack.mitre.org/techniques/T1036/005/) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1053.005](https://attack.mitre.org/techniques/T1053/005/) Scheduled Task — Persistence — observed in 2 of 2 tracked threats
- [T1056.001](https://attack.mitre.org/techniques/T1056/001/) Keylogging — Credential Access — observed in 2 of 2 tracked threats
- [T1059.001](https://attack.mitre.org/techniques/T1059/001/) PowerShell — Execution — observed in 2 of 2 tracked threats
- [T1059.003](https://attack.mitre.org/techniques/T1059/003/) Windows Command Shell — Execution — observed in 2 of 2 tracked threats
- [T1113](https://attack.mitre.org/techniques/T1113/) Screen Capture — Collection — observed in 2 of 2 tracked threats
- [T1123](https://attack.mitre.org/techniques/T1123/) Audio Capture — Collection — observed in 2 of 2 tracked threats
- [T1125](https://attack.mitre.org/techniques/T1125/) Video Capture — Collection — observed in 2 of 2 tracked threats
- [T1204.002](https://attack.mitre.org/techniques/T1204/002/) User Execution: Malicious File — Execution — observed in 2 of 2 tracked threats
- [T1497](https://attack.mitre.org/techniques/T1497/) Virtualization/Sandbox Evasion — Discovery — observed in 2 of 2 tracked threats
- [T1528](https://attack.mitre.org/techniques/T1528/) Steal Application Access Token — Credential Access — observed in 2 of 2 tracked threats
- [T1539](https://attack.mitre.org/techniques/T1539/) Steal Web Session Cookie — Credential Access — observed in 2 of 2 tracked threats
- [T1543.003](https://attack.mitre.org/techniques/T1543/003/) Create or Modify System Process: Windows Service — Persistence — observed in 2 of 2 tracked threats
- [T1547.001](https://attack.mitre.org/techniques/T1547/001/) Registry Run Keys / Startup Folder — Persistence — observed in 2 of 2 tracked threats

## Tracked threats

- [CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-Fi](https://intel.threadlinqs.com/threat/TL-2026-1857) — HIGH
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 Tokens](https://intel.threadlinqs.com/threat/TL-2026-1808) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Storm-2945
