logo

Storm-0501’s evolving techniques lead to cloud-based ransomware

ID: 02b1c2f5-05a1-5877-b599-7340f1e5d4e9

STIX ID: report--02b1c2f5-05a1-5877-b599-7340f1e5d4e9

Feed Name: Microsoft Security

Threat Score
85/100

Date Published: 2025-08-27

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes Storm-0501’s evolution to cloud-based ransomware: after compromising on-premises Active Directory and Entra Connect servers, the actor escalated to Entra ID Global Administrator, created a federated-domain backdoor, exposed and exfiltrated Azure Storage accounts, deleted backups and snapshots, then encrypted or destroyed remaining cloud data to extort victims; the report includes detailed TTPs, detection queries, and mitigation guidance for hybrid cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.