logo

Storm-0501 hackers shift to ransomware attacks in the cloud

ID: 67ddfa9b-f58d-5c03-bf91-9feaf132b121

STIX ID: report--67ddfa9b-f58d-5c03-bf91-9feaf132b121

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-08-27

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Microsoft warns that Storm-0501 has evolved from deploying on-premises ransomware to cloud-native attacks that compromise Entra ID and Azure environments, use stolen Directory Synchronization Accounts and malicious federated domains to escalate to Owner roles, exfiltrate and destroy Azure Storage and backups, create Key Vaults and customer-managed keys to render cloud data inaccessible, and extort victims via compromised Microsoft Teams accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.