ATT&CKReferencesMicrosoft Storm-501 Sabbath Ransomware Embargo September 2024

Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupStorm-0501

Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.

T1036.004
Masquerade Task or Service
GroupStorm-0501

Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe.

T1053.005
Scheduled Task
GroupStorm-0501

Storm-0501 had used a scheduled task named “SysUpdate” that was registered via GPO on devices in the network to distribute the Embargo ransomware.

T1057
Process Discovery
GroupStorm-0501

Storm-0501 has discovered running processes through `tasklist.exe`.

T1059.001
PowerShell
GroupStorm-0501

Storm-0501 has leveraged PowerShell to execute commands and scripts.

T1078.004
Cloud Accounts
GroupStorm-0501

Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment.

T1082
System Information Discovery
GroupStorm-0501

Storm-0501 has leveraged native Windows tools and commands such as `systeminfo` and open-source tools including OSQuery and ossec-win32 to query details about the endpoint.

T1087.002
Domain Account
GroupStorm-0501

Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts.

T1110
Brute Force
GroupStorm-0501

Storm-0501 has leveraged brute force attacks to obtain credentials.

T1190
Exploit Public-Facing Application
GroupStorm-0501

Storm-0501 has exploited N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203).

T1218.010
Regsvr32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe.

T1218.011
Rundll32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe.

T1219.002
Remote Desktop Software
GroupStorm-0501

Storm-0501 has used legitimate remote monitoring and management (RMM) tools including AnyDesk, NinjaOne, and Level.io.

T1482
Domain Trust Discovery
GroupStorm-0501

Storm-0501 has used Windows native utility Nltest `nltest.exe` for discovery.

T1484.001
Group Policy Modification
GroupStorm-0501

Storm-0501 distributed Group Policy Objects to tamper with security products.

T1484.002
Trust Modification
GroupStorm-0501

Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use.

T1555.005
Password Managers
GroupStorm-0501

Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1.

T1567.002
Exfiltration to Cloud Storage
GroupStorm-0501

Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI).

T1588.006
Vulnerabilities
GroupStorm-0501

Storm-0501 has obtained capabilities to exploit N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.