Storm-0501 hackers shift to ransomware attacks in the cloud
ID: 67ddfa9b-f58d-5c03-bf91-9feaf132b121
STIX ID: report--67ddfa9b-f58d-5c03-bf91-9feaf132b121
Feed Name: Bleeping Computer
Threat Score
Microsoft warns that Storm-0501 has evolved from deploying on-premises ransomware to cloud-native attacks that compromise Entra ID and Azure environments, use stolen Directory Synchronization Accounts and malicious federated domains to escalate to Owner roles, exfiltrate and destroy Azure Storage and backups, create Key Vaults and customer-managed keys to render cloud data inaccessible, and extort victims via compromised Microsoft Teams accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
