logo

Storm-0501 attacking hybrid environments with ransomware (Campaign)

ID: 3380c2de-d31a-59fb-b16b-b91cc6236903

STIX ID: report--3380c2de-d31a-59fb-b16b-b91cc6236903

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2024-09-26

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Storm-0501 is a ransomware-focused threat actor expanding operations into hybrid cloud environments; the group gains initial access through phishing and public-facing application exploits, steals credentials (e.g., Mimikatz), uses Cobalt Strike for C2, establishes persistence (scheduled tasks, new accounts), exfiltrates sensitive data, and deploys custom encryption to lock both on-premises and cloud-hosted assets, including VMs and cloud storage while exploiting IAM misconfigurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.