LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1053: Storm-0501

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.[1][2][3][4]

EnterpriseG1053GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1053: Storm-0501 describes [Storm-0501](https://attack.mitre.org/groups/G1053) is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. [Storm-0501](https://attack.mitre.org/groups/G1053) has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, [BlackCat](https://attack.mitre.org/software/S1068), Hunters International, [LockBit 3.0](https://attack.mitre.org/software/S1202), and [Embar...

Executive priority

G1053: Storm-0501 is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1053: Storm-0501 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1053: Storm-0501 appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Storm-0501

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

42 rows
DomainIDNameRelationship / procedure
EnterpriseT1219.002Remote Desktop SoftwareSub-technique

Storm-0501 has used legitimate remote monitoring and management (RMM) tools including AnyDesk, NinjaOne, and Level.io.[2]

EnterpriseT1537Transfer Data to Cloud Account

Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI.[3]

EnterpriseT1490Inhibit System Recovery

Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration.[3] Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`, `Microsoft.Compute/restorePointCollections/delete`, `Microsoft.Storage/storageAccounts/delete`, and `Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete`.[3]

EnterpriseT1484.001Group Policy ModificationSub-technique

Storm-0501 distributed Group Policy Objects to tamper with security products.[2]

EnterpriseT1530Data from Cloud Storage

Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration.[3]

EnterpriseT1059.001PowerShellSub-technique

Storm-0501 has leveraged PowerShell to execute commands and scripts.[2][3]

EnterpriseT1485Data Destruction

Storm-0501 has destroyed data and backup files.[3]

EnterpriseT1053.005Scheduled TaskSub-technique

Storm-0501 had used a scheduled task named “SysUpdate” that was registered via GPO on devices in the network to distribute the Embargo ransomware.[2]

EnterpriseT1087.004Cloud AccountSub-technique

Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound.[3]

EnterpriseT1526Cloud Service Discovery

Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies.[3]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Storm-0501 has exfiltrated stolen data to the MEGA file sharing site.[4] Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync.[2] Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI).[3]

EnterpriseT1059.009Cloud APISub-technique

Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments.[3]

EnterpriseT1021.007Cloud ServicesSub-technique

Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment.[3]

EnterpriseT1021.006Windows Remote ManagementSub-technique

Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution.[3]

EnterpriseT1190Exploit Public-Facing Application

Storm-0501 has exploited N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203).[2]

EnterpriseT1057Process Discovery

Storm-0501 has discovered running processes through `tasklist.exe`.[2]

EnterpriseT1518.001Security Software DiscoverySub-technique

Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`.[3]

EnterpriseT1486Data Encrypted for Impact

Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware.[3]

EnterpriseT1657Financial Theft

Storm-0501 has engaged in double-extortion ransomware, exfiltrating data and directly contacting victims when the primary organization refuses to pay along with posting data on their data leak sites.[1][3][4]

EnterpriseT1078.004Cloud AccountsSub-technique

Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password.[2] Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments.[3] Storm-0501 has leveraged Storage Account Access Keys within the victim environment.[3]

EnterpriseT1218.010Regsvr32Sub-technique

Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe.[2]

EnterpriseT1555.006Cloud Secrets Management StoresSub-technique

Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`.[3]

EnterpriseT1555.005Password ManagersSub-technique

Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1.[2]

EnterpriseT1484.002Trust ModificationSub-technique

Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use.[2][3]

EnterpriseT1580Cloud Infrastructure Discovery

Storm-0501 has enumerated compromised cloud environments to identify critical assets, data stores, and back resources.[3]

EnterpriseT1482Domain Trust Discovery

Storm-0501 has used Windows native utility Nltest `nltest.exe` for discovery.[2]

EnterpriseT1578.003Delete Cloud InstanceSub-technique

Storm-0501 has conducted mass deletion of cloud data stores and resources from Azure subscriptions.[3]

EnterpriseT1082System Information Discovery

Storm-0501 has leveraged native Windows tools and commands such as `systeminfo` and open-source tools including OSQuery and ossec-win32 to query details about the endpoint.[2]

EnterpriseT1027.002Software PackingSub-technique

Storm-0501 has used Themida to pack Cobalt Strike payloads.[4]

EnterpriseT1614.001System Language DiscoverySub-technique

Storm-0501 has identified system language codes on a compromised host to determine if the victim falls under a non-supported language code that is prohibited for targeting, including victims associated with Russia and other Commonwealth of Independent States (CIS) that may draw attention of law enforcement in countries where the ransomware operator or affiliates may reside/operate from.[1][4]

EnterpriseT1552.004Private KeysSub-technique

Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation.[3]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe.[2]

EnterpriseT1098.003Additional Cloud RolesSub-technique

Storm-0501 has elevated their access to Azure resources using `Microsoft.Authorization/elevateAccess/action` and `Microsoft.Authorization/roleAssignments/write` operations to gain User Access Administrator and Owner Azure roles over the victims’ Azure subscriptions.[3]

EnterpriseT1087.002Domain AccountSub-technique

Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts.[2]

EnterpriseT1218.011Rundll32Sub-technique

Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe.[2]

EnterpriseT1587.003Digital CertificatesSub-technique

Storm-0501 has utilized their own self-signed TLS certificate “Microsoft IT TLS CA 5” with their infrastructure.[4]

EnterpriseT1588.006VulnerabilitiesSub-technique

Storm-0501 has obtained capabilities to exploit N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203).[2]

EnterpriseT1556.009Conditional Access PoliciesSub-technique

Storm-0501 has registered their own MFA method, and leveraged a victim hybrid joined server to circumvent Conditional Access Policies.[3]

EnterpriseT1110Brute Force

Storm-0501 has leveraged brute force attacks to obtain credentials.[2]

EnterpriseT1098.001Additional Cloud CredentialsSub-technique

Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method.[3]

EnterpriseT1003.006DCSyncSub-technique

Storm-0501 has utilized DCSync to extract credentials from victims.[3]

EnterpriseT1003OS Credential Dumping

Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.[2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0357: Impacket

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.[1]

LinuxmacOSWindows
ToolEnterprise

S0057: Tasklist

The Tasklist utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or a remote computer. It is packaged with Windows operating systems and can be executed from the command-line interface. [1]

MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
MalwareEnterprise

S1247: Embargo

Embargo is a ransomware variant written in Rust that has been active since at least May 2024.[1][2] Embargo ransomware operations are associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid.[1][2] Embargo ransomware has been known to be delivered through a loader known as MDeployer which also leverages a malware component known as MS4Killer that facilitates termination of processes operating on the victim hosts.[2] Embargo is also reportedly a Ransomware as a Service (RaaS).[2]

ESXiLinuxWindows
ToolEnterprise

S1040: Rclone

Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.[1][2][3][4][5]

LinuxWindowsmacOS
ToolEnterprise

S0359: Nltest

Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.[1]

Windows
ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
ToolEnterprise

S0677: AADInternals

AADInternals is a PowerShell-based framework for administering, enumerating, and exploiting Azure Active Directory. The tool is publicly available on GitHub.[1][2]

WindowsOffice SuiteIdentity Provider
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.0
Created
Modified
Raw hash
29da9f5263350e4a...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.0Current bundle29da9f526335…
19.11.0Older bundleccdd8b9ffe35…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Avertium Storm-0501 Sabbath Ransomware Arcane January 2022

    Avertium. (2022, January 11). An In-Depth Look at Ransomware Gang, Sabbath. Retrieved October 19, 2025.

    Open source URL
  2. [2]
    Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

    Open source URL
  3. [3]
    Microsoft Storm-0501 Embargo Ransomware August 2025

    Microsoft Threat Intelligence. (2025, August 27). Storm-0501’s evolving techniques lead to cloud-based ransomware. Retrieved October 19, 2025.

    Open source URL
  4. [4]
    Google Mandiant Storm-0501 Sabbath Ransomware November 2021

    Tyler McLellan, Brandan Schondorfer. (2021, November 29). Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again. Retrieved October 19, 2025.

    Open source URL
  5. [5]
    mitre-attackG1053
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.