Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupStorm-0501 | Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information. |
| T1036.004 Masquerade Task or Service |
GroupStorm-0501 | Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe. |
| T1053.005 Scheduled Task |
GroupStorm-0501 | Storm-0501 had used a scheduled task named “SysUpdate” that was registered via GPO on devices in the network to distribute the Embargo ransomware. |
| T1057 Process Discovery |
GroupStorm-0501 | Storm-0501 has discovered running processes through `tasklist.exe`. |
| T1059.001 PowerShell |
GroupStorm-0501 | Storm-0501 has leveraged PowerShell to execute commands and scripts. |
| T1078.004 Cloud Accounts |
GroupStorm-0501 | Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment. |
| T1082 System Information Discovery |
GroupStorm-0501 | Storm-0501 has leveraged native Windows tools and commands such as `systeminfo` and open-source tools including OSQuery and ossec-win32 to query details about the endpoint. |
| T1087.002 Domain Account |
GroupStorm-0501 | Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts. |
| T1110 Brute Force |
GroupStorm-0501 | Storm-0501 has leveraged brute force attacks to obtain credentials. |
| T1190 Exploit Public-Facing Application |
GroupStorm-0501 | Storm-0501 has exploited N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203). |
| T1218.010 Regsvr32 |
GroupStorm-0501 | Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe. |
| T1218.011 Rundll32 |
GroupStorm-0501 | Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe. |
| T1219.002 Remote Desktop Software |
GroupStorm-0501 | Storm-0501 has used legitimate remote monitoring and management (RMM) tools including AnyDesk, NinjaOne, and Level.io. |
| T1482 Domain Trust Discovery |
GroupStorm-0501 | Storm-0501 has used Windows native utility Nltest `nltest.exe` for discovery. |
| T1484.001 Group Policy Modification |
GroupStorm-0501 | Storm-0501 distributed Group Policy Objects to tamper with security products. |
| T1484.002 Trust Modification |
GroupStorm-0501 | Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use. |
| T1555.005 Password Managers |
GroupStorm-0501 | Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1. |
| T1567.002 Exfiltration to Cloud Storage |
GroupStorm-0501 | Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI). |
| T1588.006 Vulnerabilities |
GroupStorm-0501 | Storm-0501 has obtained capabilities to exploit N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.