logo

Storm-0501: Ransomware attacks expanding to hybrid cloud environments

ID: 59479449-3e2b-5c92-8739-405562b2f824

STIX ID: report--59479449-3e2b-5c92-8739-405562b2f824

Feed Name: Microsoft Security

Threat Score
80/100

Date Published: 2024-09-26

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes Storm-0501, a financially motivated ransomware-as-a-service affiliate group that has shifted from on-premises ransomware to cloud-focused operations: they exploit unpatched public-facing servers and weak credentials to gain admin access, perform discovery and credential theft, exfiltrate data (via renamed Rclone), abuse Microsoft Entra Connect (sync) accounts and AADInternals to pivot and create federated-domain backdoors that bypass MFA, and deploy Embargo ransomware; the report provides IOCs, detection queries (Defender XDR / Sentinel), and prescriptive mitigations to protect hybrid cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.