Storm-0501

MITRE ATT&CK: G1053 View on attack.mitre.org

Aliases: Storm-0501

First seen
2021-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:17:54

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications government-and-public-sector retail-and-hospitality

Context

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.

Detection coverage

  • 145 YARA rules
  • 650 Sigma rules

Malware & tools used

  • Remote Desktop Software (attack-pattern)
  • Transfer Data to Cloud Account (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Group Policy Modification (attack-pattern)
  • Data from Cloud Storage (attack-pattern)
  • PowerShell (attack-pattern)
  • Data Destruction (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Cloud Account (attack-pattern)
  • DCSync (attack-pattern)
  • Cloud Service Discovery (attack-pattern)
  • Exfiltration to Cloud Storage (attack-pattern)
  • Cloud API (attack-pattern)
  • Cloud Services (attack-pattern)
  • Windows Remote Management (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Process Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Financial Theft (attack-pattern)
  • Cloud Accounts (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Cloud Secrets Management Stores (attack-pattern)
  • Password Managers (attack-pattern)
  • Trust Modification (attack-pattern)

Reports & references

  • Microsoft — Storm 0501 Ransomware Attacks Expanding To Hybrid Cloud Environments (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • MITRE ATT&CK — G1053 (report)
  • cloud.google.com — Sabbath Ransomware Affiliate (report)
  • avertium.com — In Depth Look At Sabbath Ransomware Gang (report)
  • Microsoft — Storm 0501S Evolving Techniques Lead To Cloud Based Ransomware (report)

Attributed from

  • Storm-0501 Hybrid Cloud Compromise (campaign)
  • UNC2190 2021 Ransomware Activity (campaign)

External references