logo

Storm-0501 Targeting Hybrid Environments with Ransomware (Campaign)

ID: aa938a25-c6ca-50a6-9f25-f2f1b6a95a43

STIX ID: report--aa938a25-c6ca-50a6-9f25-f2f1b6a95a43

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2024-09-26

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Storm-0501 is conducting multi-stage, financially motivated ransomware campaigns targeting hybrid cloud environments across U.S. sectors by exploiting public-facing vulnerabilities (e.g., Zoho ManageEngine CVE-2022-47966, Citrix NetScaler CVE-2023-4966), abusing weak credentials and Entra Connect Sync to pivot to cloud tenants, and using tools like Cobalt Strike, AnyDesk, OSQuery, Impacket SecretsDump, and Rclone for reconnaissance, credential theft, lateral movement, persistence, and data exfiltration before deploying ransomware (Embargo).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.