Storm-0501: Ransomware attacks expanding to hybrid cloud environments
ID: 59479449-3e2b-5c92-8739-405562b2f824
STIX ID: report--59479449-3e2b-5c92-8739-405562b2f824
Feed Name: Microsoft Security
Microsoft Threat Intelligence describes Storm-0501, a financially motivated ransomware-as-a-service affiliate group that has shifted from on-premises ransomware to cloud-focused operations: they exploit unpatched public-facing servers and weak credentials to gain admin access, perform discovery and credential theft, exfiltrate data (via renamed Rclone), abuse Microsoft Entra Connect (sync) accounts and AADInternals to pivot and create federated-domain backdoors that bypass MFA, and deploy Embargo ransomware; the report provides IOCs, detection queries (Defender XDR / Sentinel), and prescriptive mitigations to protect hybrid cloud environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
