logo

Storm-0501 Hits Enterprise With 'Cloud-Based Ransomware' Attack

ID: df988f4c-299a-514e-90ed-3f4562080d5d

STIX ID: report--df988f4c-299a-514e-90ed-3f4562080d5d

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-08-27

Date Updated: 2026-05-08

Author: Alexander Culafi

...
...

Microsoft published research on Storm-0501's cloud-based ransomware campaign in which the actor leveraged weak credential hygiene and Entra Connect Sync Directory Synchronization Accounts to move from on-premises into multiple Azure/Entra tenants, escalate to Global Administrator, exfiltrate large volumes of data, mass-delete Azure resources, and attempt to render remaining data inaccessible by creating a malicious Key Vault and customer-managed key; the actor then issued a ransom demand via a compromised Teams account. Microsoft recommends restricting DSA permissions, enforcing MFA and conditional access, using least privilege, deploying tamper protection and EDR in block mode, and enabling automated investigation and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.