Storm-1084
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranStorm-1084 is Microsoft's formal name for the MuddyWater subgroup previously tracked as DEV-1084, responsible for destructive cyberattacks against Israeli organizations in 2023. The subgroup leveraged initial access established by the broader Mango Sandstorm (MuddyWater) cluster to deploy DarkBit, a ransomware-wiper hybrid that caused significant data loss and operational disruption. Storm-1084 represents a destructive operational capability bolted onto MuddyWater's established espionage infrastructure, reflecting Iran's pattern of using espionage access as a foundation for subsequent disruptive attacks.
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.