Microsoft Threat Intelligence. (2025, August 27). Storm-0501’s evolving techniques lead to cloud-based ransomware. Retrieved October 19, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.006 DCSync |
GroupStorm-0501 | Storm-0501 has utilized DCSync to extract credentials from victims. |
| T1021.006 Windows Remote Management |
GroupStorm-0501 | Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution. |
| T1021.007 Cloud Services |
GroupStorm-0501 | Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment. |
| T1059.001 PowerShell |
GroupStorm-0501 | Storm-0501 has leveraged PowerShell to execute commands and scripts. |
| T1059.009 Cloud API |
GroupStorm-0501 | Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments. |
| T1078.004 Cloud Accounts |
GroupStorm-0501 | Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment. |
| T1087.004 Cloud Account |
GroupStorm-0501 | Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound. |
| T1098.001 Additional Cloud Credentials |
GroupStorm-0501 | Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method. |
| T1098.003 Additional Cloud Roles |
GroupStorm-0501 | Storm-0501 has elevated their access to Azure resources using `Microsoft.Authorization/elevateAccess/action` and `Microsoft.Authorization/roleAssignments/write` operations to gain User Access Administrator and Owner Azure roles over the victims’ Azure subscriptions. |
| T1484.002 Trust Modification |
GroupStorm-0501 | Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use. |
| T1485 Data Destruction |
GroupStorm-0501 | Storm-0501 has destroyed data and backup files. |
| T1486 Data Encrypted for Impact |
GroupStorm-0501 | Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware. |
| T1490 Inhibit System Recovery |
GroupStorm-0501 | Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`, |
| T1518.001 Security Software Discovery |
GroupStorm-0501 | Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`. |
| T1526 Cloud Service Discovery |
GroupStorm-0501 | Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies. |
| T1530 Data from Cloud Storage |
GroupStorm-0501 | Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration. |
| T1537 Transfer Data to Cloud Account |
GroupStorm-0501 | Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI. |
| T1552.004 Private Keys |
GroupStorm-0501 | Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation. |
| T1555.006 Cloud Secrets Management Stores |
GroupStorm-0501 | Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`. |
| T1556.009 Conditional Access Policies |
GroupStorm-0501 | Storm-0501 has registered their own MFA method, and leveraged a victim hybrid joined server to circumvent Conditional Access Policies. |
| T1567.002 Exfiltration to Cloud Storage |
GroupStorm-0501 | Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI). |
| T1578.003 Delete Cloud Instance |
GroupStorm-0501 | Storm-0501 has conducted mass deletion of cloud data stores and resources from Azure subscriptions. |
| T1580 Cloud Infrastructure Discovery |
GroupStorm-0501 | Storm-0501 has enumerated compromised cloud environments to identify critical assets, data stores, and back resources. |
| T1657 Financial Theft |
GroupStorm-0501 | Storm-0501 has engaged in double-extortion ransomware, exfiltrating data and directly contacting victims when the primary organization refuses to pay along with posting data on their data leak sites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.