Storm-0501
MITRE ATT&CK: G1053 View on attack.mitre.org
Aliases: Storm-0501
- First seen
- 2021-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:17:54
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications government-and-public-sector retail-and-hospitality
Context
Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.
Detection coverage
- 145 YARA rules
- 650 Sigma rules
Malware & tools used
- Remote Desktop Software (attack-pattern)
- Transfer Data to Cloud Account (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Group Policy Modification (attack-pattern)
- Data from Cloud Storage (attack-pattern)
- PowerShell (attack-pattern)
- Data Destruction (attack-pattern)
- Scheduled Task (attack-pattern)
- Cloud Account (attack-pattern)
- DCSync (attack-pattern)
- Cloud Service Discovery (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- Cloud API (attack-pattern)
- Cloud Services (attack-pattern)
- Windows Remote Management (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Process Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Financial Theft (attack-pattern)
- Cloud Accounts (attack-pattern)
- Regsvr32 (attack-pattern)
- Cloud Secrets Management Stores (attack-pattern)
- Password Managers (attack-pattern)
- Trust Modification (attack-pattern)
Reports & references
- Microsoft — Storm 0501 Ransomware Attacks Expanding To Hybrid Cloud Environments (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- MITRE ATT&CK — G1053 (report)
- cloud.google.com — Sabbath Ransomware Affiliate (report)
- avertium.com — In Depth Look At Sabbath Ransomware Gang (report)
- Microsoft — Storm 0501S Evolving Techniques Lead To Cloud Based Ransomware (report)
Attributed from
- Storm-0501 Hybrid Cloud Compromise (campaign)
- UNC2190 2021 Ransomware Activity (campaign)
External references
- mitre-attack — G1053
- Avertium Storm-0501 Sabbath Ransomware Arcane January 2022
- Microsoft Storm-501 Sabbath Ransomware Embargo September 2024
- Microsoft Storm-0501 Embargo Ransomware August 2025
- Google Mandiant Storm-0501 Sabbath Ransomware November 2021
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy