Storm-0501
Overview
Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.
Naming & attribution
Storm-0501 is tracked under 1 names across the industry. It uses 42 documented ATT&CK techniques — more than 78% of the 174 groups tracked here. Activity attributed since 2021.
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1098.001Additional Cloud Credentials — used by 1 of 174 groups -
T1526Cloud Service Discovery — used by 1 of 174 groups -
T1087.004Cloud Account — used by 2 of 174 groups -
T1484.002Trust Modification — used by 2 of 174 groups -
T1555.006Cloud Secrets Management Stores — used by 2 of 174 groups -
T1556.009Conditional Access Policies — used by 2 of 174 groups -
T1578.003Delete Cloud Instance — used by 2 of 174 groups -
T1580Cloud Infrastructure Discovery — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Scattered Spider — 17 shared techniques (19% overlap)
- VOID MANTICORE Iran — 13 shared techniques (14% overlap)
- BlackByte — 11 shared techniques (14% overlap)
- ToddyCat — 7 shared techniques (12% overlap)
- APT38 North Korea — 10 shared techniques (11% overlap)
- Medusa Group — 10 shared techniques (11% overlap)
Malware families with current indicators
One family attributed to Storm-0501, carrying 9 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Embargo 9 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Destructive / data-wiping operations — ATT&CK T1485
- Exploitation of public-facing / client applications — ATT&CK T1190
TTPs — 42 techniques across 13 tactics
Resource Development
-
T1587.003Digital Certificates -
T1588.006Vulnerabilities
Initial Access
Execution
-
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.009Cloud API
Persistence
-
T1098.001Additional Cloud Credentials -
T1098.003Additional Cloud Roles
Stealth
-
T1027.002Software Packing -
T1036.004Masquerade Task or Service -
T1078.004Cloud Accounts -
T1218.010Regsvr32 -
T1218.011Rundll32
Defense Impairment
-
T1484.001Group Policy Modification -
T1484.002Trust Modification -
T1556.009Conditional Access Policies -
T1578.003Delete Cloud Instance
Credential Access
-
T1003OS Credential Dumping -
T1003.006DCSync -
T1110Brute Force -
T1552.004Private Keys -
T1555.005Password Managers -
T1555.006Cloud Secrets Management Stores
Discovery
-
T1057Process Discovery -
T1082System Information Discovery -
T1087.002Domain Account -
T1087.004Cloud Account -
T1482Domain Trust Discovery -
T1518.001Security Software Discovery -
T1526Cloud Service Discovery -
T1580Cloud Infrastructure Discovery -
T1614.001System Language Discovery
Lateral Movement
-
T1021.006Windows Remote Management -
T1021.007Cloud Services
Collection
-
T1530Data from Cloud Storage
Command and Control
-
T1219.002Remote Desktop Software
Exfiltration
-
T1537Transfer Data to Cloud Account -
T1567.002Exfiltration to Cloud Storage
Impact
-
T1485Data Destruction -
T1486Data Encrypted for Impact -
T1490Inhibit System Recovery -
T1657Financial Theft
Tools & malware (8)
Impacket · Tasklist · Cobalt Strike · Embargo · Rclone · Nltest · Net · AADInternals
Reporting (3)
- Storm-0501’s evolving techniques lead to cloud-based ransomware — Microsoft Threat Intelligence
- Storm-0501: Ransomware attacks expanding to hybrid cloud environments — Microsoft Threat Intelligence
- An In-Depth Look at Ransomware Gang, Sabbath — Avertium