Actors Insights|Latest update27/08/2026

Storm-1084

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Storm-1084 is Microsoft's formal name for the MuddyWater subgroup previously tracked as DEV-1084, responsible for destructive cyberattacks against Israeli organizations in 2023. The subgroup leveraged initial access established by the broader Mango Sandstorm (MuddyWater) cluster to deploy DarkBit, a ransomware-wiper hybrid that caused significant data loss and operational disruption. Storm-1084 represents a destructive operational capability bolted onto MuddyWater's established espionage infrastructure, reflecting Iran's pattern of using espionage access as a foundation for subsequent disruptive attacks.

This threat actor previously was known as DEV-1084
First Seen:Mar 2023
Last Seen:Apr 2023
Indexed Reports:0
Public IOCs:0
Cluster: MuddyWaterMisp: Storm-1084
also known as:
DEV-1084 (Microsoft)Storm-1084 (Microsoft)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.