Threat group.View on attack.mitre.org
Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.
| Technique | Procedure example |
|---|---|
| T1003 OS Credential Dumping |
Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information. |
| T1003.006 DCSync |
Storm-0501 has utilized DCSync to extract credentials from victims. |
| T1021.006 Windows Remote Management |
Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution. |
| T1021.007 Cloud Services |
Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment. |
| T1027.002 Software Packing |
Storm-0501 has used Themida to pack Cobalt Strike payloads. |
| T1036.004 Masquerade Task or Service |
Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe. |
| T1053.005 Scheduled Task |
Storm-0501 had used a scheduled task named “SysUpdate” that was registered via GPO on devices in the network to distribute the Embargo ransomware. |
| T1057 Process Discovery |
Storm-0501 has discovered running processes through `tasklist.exe`. |
| T1059.001 PowerShell |
Storm-0501 has leveraged PowerShell to execute commands and scripts. |
| T1059.009 Cloud API |
Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments. |
| T1078.004 Cloud Accounts |
Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment. |
| T1082 System Information Discovery |
Storm-0501 has leveraged native Windows tools and commands such as `systeminfo` and open-source tools including OSQuery and ossec-win32 to query details about the endpoint. |
| T1087.002 Domain Account |
Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts. |
| T1087.004 Cloud Account |
Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound. |
| T1098.001 Additional Cloud Credentials |
Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.