Home/Threat Actor/Storm-0861
Threat Actor

Storm-0861

storm_0861 · iran · active since 2022-01

Storm-0861 (Microsoft canonical designation.

Storm-* prefix indicates developing/partially-attributed clusters not yet promoted to Sandstorm = Iran nation-themed naming convention) is an Iran-affiliated cyber operations cluster tracked by Microsoft Threat Intelligence in association with critical infrastructure targeting, OT/ICS environment intrusions, and selectively Israel and Western infrastructure targeting; Microsoft December 2023 reporting documented Storm-0861 in operational adjacency to CyberAv3ngers operations against US water utility operators (Unitronics PLC-controlled OT environments including Aliquippa Municipal Water Authority November-December 2023 attack), exact operational relationship between Storm-0861 and CyberAv3ngers (cyberav3ngers.yaml) remains partially analytical and open in public reporting.

thin public technical documentation relative to higher-profile Iran-affiliated clusters (APT34/OilRig, APT35/Charming Kitten, MuddyWater, Agrius, Scarred Manticore/UNC1860, Cotton Sandstorm)

positioned within operational-impact-capable sub-ecosystem of Iran- aligned operations alongside Agrius, CyberAv3ngers, and Predatory Sparrow, all curated separately in this corpus.

iran confidence: medium 5 aliases

Profile

Storm-0861 (Microsoft canonical designation under Microsoft's threat-actor naming framework, where Storm-* designations indicate developing or partially-attributed clusters not yet promoted to Microsoft's nation-themed Sandstorm = Iran naming convention) is an Iran-affiliated cyber operations cluster tracked by Microsoft Threat Intelligence in association with operations consistent with broader Iran- affiliated cyber-operations ecosystem patterns including critical infrastructure targeting, OT/ICS environment intrusions, and selectively Israel and Western infrastructure targeting. The cluster's public-record documentation is comparatively thinner than Iran-affiliated clusters with high-profile disclosed operations (APT34 / OilRig, APT35 / Charming Kitten, MuddyWater, Agrius, Scarred Manticore / UNC1860, Cotton Sandstorm), Storm-0861 operational visibility in public reporting is primarily through Microsoft threat intelligence reporting rather than through canonical disclosure reports detailing specific named operations. Microsoft's December 2023 reporting on Iran-aligned operational activity against US water utility operators (CyberAv3ngers operations against Unitronics PLC-controlled water utility OT environments) documented Storm-0861 in operational adjacency to the CyberAv3ngers operations.

The CyberAv3ngers operations included the November-December 2023 attacks against the Aliquippa Municipal Water Authority (Pennsylvania) and other US water utilities operating Unitronics PLC infrastructure, operations claimed by the CyberAv3ngers persona following the October 2023 Hamas attack on Israel. The exact operational relationship between Storm-0861 and CyberAv3ngers (curated separately at cyberav3ngers.yaml) remains partially analytical and open in public reporting. The cluster's targeting profile (critical infrastructure including US water utilities, OT environments, selectively Israeli and Western infrastructure) operationally distinguishes Storm-0861 from purely-espionage-focused Iran-affiliated clusters and positions the cluster within the operational-impact-capable sub-ecosystem of Iran-aligned operations alongside Agrius (destructive operations), CyberAv3ngers (OT-targeting), and Predatory Sparrow (sabotage-adjacent operations).

Operational tradecraft includes spearphishing operations, perimeter-appliance N-day exploitation for initial access, credential harvesting infrastructure, conventional lateral movement, and operational coordination with adjacent Iran- affiliated clusters within the broader Iran-aligned operational ecosystem. Storm-0861 is curated as a thin-documentation entry relative to flagship Iran-affiliated cluster entries in this corpus. The entry is structurally significant for Iran-affiliated cyber-operations ecosystem completeness rather than for deep technical tradecraft analysis.

Analysts requiring technical depth on Iran-affiliated cyber-operations should prioritize the higher-public- documentation cluster entries.

Aliases

5
storm_0861storm-0861storm 0861iran-affiliated-storm-0861-clusterstorm0861

Notable Campaigns

3
2023CyberAv3ngers Operational Adjacency, US Water Utility Operations (December 2023)
2022-2025Microsoft Storm-0861 Operational Tracking (2022-2025)
2022-2025Storm-0861 Iran-Affiliated Cyber-Operations Ecosystem Position

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence (MSTIC)Mandiant (Google Threat Intelligence)CrowdStrikeSentinelOneCISA (US Cybersecurity and Infrastructure Security Agency)Israeli National Cyber Directorate (INCD)Recorded Future Insikt Group
Key reporting
reportMicrosoft Threat Intelligence: Iran-Aligned Cyber Operations Targeting US Water Utilities (December 2023)
reportCISA / FBI / NSA / EPA Joint Cybersecurity Advisory: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors (AA23-335A)
reportMandiant / Google Threat Intelligence: Iran-Aligned Critical Infrastructure Targeting Analysis
reportRecorded Future Insikt Group: Iran-Aligned Operations Tracking
reportMalpedia Actor Profile: Storm-0861

Operational

State sponsor

Iran-affiliated cyber operations cluster tracked by Microsoft Threat Intelligence (canonical Storm-0861 designation under Microsoft's threat-actor naming framework, where Storm-* designations indicate developing or partially-attributed clusters not yet promoted to Microsoft's nation-themed (Sandstorm = Iran) naming convention). Storm-0861 has been tracked by Microsoft in association with operations consistent with broader Iran-affiliated cyber-operations ecosystem patterns including critical infrastructure targeting, OT/ICS environment intrusions, and selectively Israel and Western infrastructure targeting. Microsoft's December 2023 reporting on Iran-aligned operational activity against US water utility operators (CyberAv3ngers operations against Unitronics PLC-controlled water utilities) documented Storm-0861 in operational adjacency to the CyberAv3ngers operations, though the exact operational relationship between Storm-0861 and CyberAv3ngers (curated separately at cyberav3ngers.yaml) remains partially analytical and open in public reporting.

The cluster's operational origin assessment is consistent with Iran-affiliated cyber- operations ecosystem context including operational tradecraft patterns and targeting profile alignment. The cluster has not been formally attributed by any government cybersecurity authority to a specific Iranian government agency, military intelligence service (IRGC-CEC, IRGC-IO), or civilian intelligence service (MOIS). The cluster's public-record documentation is comparatively thinner than Iran-affiliated clusters with high-profile disclosed operations (APT34 / OilRig, APT35 / Charming Kitten, MuddyWater, Agrius, Scarred Manticore / UNC1860, Cotton Sandstorm).

Storm-0861 is operationally distinct from all other Iran-affiliated clusters curated separately in this corpus including APT34 / OilRig (apt34_oilrig.yaml), APT35 / Charming Kitten (apt35_charmingkitten.yaml), APT39 / Chafer (apt39_chafer.yaml), MuddyWater (muddywater.yaml), Agrius (agrius.yaml), Pioneer Kitten / Fox Kitten (pioneer_kitten_fox_kitten.yaml), Imperial Kitten / Tortoiseshell (imperial_kitten_tortoiseshell.yaml), Scarred Manticore / UNC1860 (scarred_manticore_unc1860.yaml), Cotton Sandstorm (cotton_sandstorm.yaml), CyberAv3ngers (cyberav3ngers.yaml), and Predatory Sparrow (predatory_sparrow.yaml).

Motivations
cyber_espionage, critical_infrastructure_targeting, iranian_state_strategic_priorities, operational_technology_environment_targeting, geopolitical_tension_motivated_operations
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)54/60 · 90%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)10/60 · 16%
File / malware (YARA)1/60 · 1%
Network (Suricata/Snort)18/60 · 30%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped

CVEs Exploited

2
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin