NEW: Group Profiler — instant APT intel lookup. Try it →

Storm-0501

Overview

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.

Naming & attribution

Storm-0501 is tracked under 1 names across the industry. It uses 42 documented ATT&CK techniques — more than 78% of the 174 groups tracked here. Activity attributed since 2021.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1098.001 Additional Cloud Credentials — used by 1 of 174 groups
  • T1526 Cloud Service Discovery — used by 1 of 174 groups
  • T1087.004 Cloud Account — used by 2 of 174 groups
  • T1484.002 Trust Modification — used by 2 of 174 groups
  • T1555.006 Cloud Secrets Management Stores — used by 2 of 174 groups
  • T1556.009 Conditional Access Policies — used by 2 of 174 groups
  • T1578.003 Delete Cloud Instance — used by 2 of 174 groups
  • T1580 Cloud Infrastructure Discovery — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Scattered Spider — 17 shared techniques (19% overlap)
  • VOID MANTICORE Iran — 13 shared techniques (14% overlap)
  • BlackByte — 11 shared techniques (14% overlap)
  • ToddyCat — 7 shared techniques (12% overlap)
  • APT38 North Korea — 10 shared techniques (11% overlap)
  • Medusa Group — 10 shared techniques (11% overlap)

Malware families with current indicators

One family attributed to Storm-0501, carrying 9 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Embargo 9 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Destructive / data-wiping operations — ATT&CK T1485
  • Exploitation of public-facing / client applications — ATT&CK T1190

TTPs — 42 techniques across 13 tactics

Resource Development

Initial Access

Execution

Persistence

Stealth

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Tools & malware (8)

Impacket · Tasklist · Cobalt Strike · Embargo · Rclone · Nltest · Net · AADInternals

Reporting (3)