ATT&CKGroupsStorm-0501

Storm-0501

G1053

Threat group.View on attack.mitre.org

About this group

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.

Techniques used42

Procedure examples42

TechniqueProcedure example
T1003
OS Credential Dumping

Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.

T1003.006
DCSync

Storm-0501 has utilized DCSync to extract credentials from victims.

T1021.006
Windows Remote Management

Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution.

T1021.007
Cloud Services

Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment.

T1027.002
Software Packing

Storm-0501 has used Themida to pack Cobalt Strike payloads.

T1036.004
Masquerade Task or Service

Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe.

T1053.005
Scheduled Task

Storm-0501 had used a scheduled task named “SysUpdate” that was registered via GPO on devices in the network to distribute the Embargo ransomware.

T1057
Process Discovery

Storm-0501 has discovered running processes through `tasklist.exe`.

T1059.001
PowerShell

Storm-0501 has leveraged PowerShell to execute commands and scripts.

T1059.009
Cloud API

Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments.

T1078.004
Cloud Accounts

Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment.

T1082
System Information Discovery

Storm-0501 has leveraged native Windows tools and commands such as `systeminfo` and open-source tools including OSQuery and ossec-win32 to query details about the endpoint.

T1087.002
Domain Account

Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts.

T1087.004
Cloud Account

Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound.

T1098.001
Additional Cloud Credentials

Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method.

View all 42 procedure examples

Software8

Campaigns0

None recorded.

References4

  1. Avertium Storm-0501 Sabbath Ransomware Arcane January 2022 Open source
    Avertium. (2022, January 11). An In-Depth Look at Ransomware Gang, Sabbath. Retrieved October 19, 2025.
  2. Google Mandiant Storm-0501 Sabbath Ransomware November 2021 Open source
    Tyler McLellan, Brandan Schondorfer. (2021, November 29). Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again. Retrieved October 19, 2025.
  3. Microsoft Storm-0501 Embargo Ransomware August 2025 Open source
    Microsoft Threat Intelligence. (2025, August 27). Storm-0501’s evolving techniques lead to cloud-based ransomware. Retrieved October 19, 2025.
  4. Microsoft Storm-501 Sabbath Ransomware Embargo September 2024 Open source
    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.