Storm-0501 Hits Enterprise With 'Cloud-Based Ransomware' Attack
ID: df988f4c-299a-514e-90ed-3f4562080d5d
STIX ID: report--df988f4c-299a-514e-90ed-3f4562080d5d
Feed Name: Dark Reading
Microsoft published research on Storm-0501's cloud-based ransomware campaign in which the actor leveraged weak credential hygiene and Entra Connect Sync Directory Synchronization Accounts to move from on-premises into multiple Azure/Entra tenants, escalate to Global Administrator, exfiltrate large volumes of data, mass-delete Azure resources, and attempt to render remaining data inaccessible by creating a malicious Key Vault and customer-managed key; the actor then issued a ransom demand via a compromised Teams account. Microsoft recommends restricting DSA permissions, enforcing MFA and conditional access, using least privilege, deploying tamper protection and EDR in block mode, and enabling automated investigation and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
