Embargo ransomware escalates attacks to cloud environments
ID: 8365a7a1-0141-5062-9b05-c3592eb2fb99
STIX ID: report--8365a7a1-0141-5062-9b05-c3592eb2fb99
Feed Name: Bleeping Computer
Microsoft reports that Storm-0501, a ransomware affiliate group now deploying Embargo ransomware, has shifted to targeting hybrid cloud environments by using stolen or purchased credentials, exploiting known CVEs (including Zoho ManageEngine and Citrix NetScaler flaws), and abusing Microsoft Entra ID/Entra Connect synchronization accounts to move from on-premises to cloud, establish persistence (federated domains/ImmutableId manipulation), exfiltrate data (custom Rclone), and deploy ransomware across cloud and on-prem assets; targeted sectors include hospitals, government, manufacturing, transportation, and law enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
