LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1053: Storm-0501

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.CitationAvertium Storm-0501 Sabbath Ransomware Arcane January 2022CitationMicrosoft Storm-501 Sabbath Ransomware Embargo September 2024CitationMicrosoft Storm-0501 Embargo Ransomware August 2025CitationGoogle Mandiant Storm-0501 Sabbath Ransomware November 2021

EnterpriseG1053GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Storm-0501 matters because MITRE describes it as a financially motivated cyber criminal group tied to ransomware operations and use of commodity/open-source tooling. The relationship set is especially relevant to hybrid environments: it includes Windows administration utilities, credential dumping and DCSync, WinRM lateral movement, cloud account access, cloud API execution, added cloud credentials/roles, Rclone, Cobalt Strike, and Embargo ransomware. For leaders, the decision point is whether ransomware readiness covers identity, Active Directory, cloud tenants, and data movement together—not just endpoint malware blocking.

Executive priority

Treat this as a ransomware resilience and hybrid identity governance use case. Executives should ask whether the organization can prove control over privileged domain accounts, cloud admin roles, added credentials, remote management pathways, and unusual bulk file synchronization. Budget and audit attention should prioritize evidence that identity changes, cloud API activity, endpoint execution, and lateral movement are logged, retained, and actionable during an incident. Because ATT&CK provides no official detection text for this group object, local validation is required rather than assuming existing tools provide coverage.

Technical view

SOC and IR teams should map coverage from the listed relationships rather than from the group object alone. Validate detections for credential access such as OS Credential Dumping and DCSync; lateral movement through WinRM and cloud services; execution through PowerShell and cloud APIs; persistence or privilege escalation through added cloud credentials and roles; discovery through Net, Nltest, Tasklist, domain/cloud account enumeration, process discovery, and system information discovery; and data movement/tooling indicators associated with Rclone, Cobalt Strike, Impacket, AADInternals, and Embargo. Prioritize correlation across endpoint, Active Directory, identity provider, SaaS/IaaS, and network telemetry because the supplied relationships span on-premises Windows and cloud identity/control planes.

Likely telemetry

  • Endpoint process creation and command-line logs for Net, Nltest, Tasklist, PowerShell, schtasks, WinRM-related activity, Rclone, Impacket, AADInternals, and suspicious packed binaries
  • Windows security, service, scheduled task, PowerShell, and remote management logs
  • Domain controller and directory replication telemetry relevant to DCSync and privileged account activity
  • Identity provider and cloud audit logs for sign-ins, cloud API execution, role assignment changes, service principal/application credential additions, and cloud account enumeration
  • Network telemetry for remote administration, SMB/Windows administrative activity where logged, cloud service access, and large or unusual synchronization flows

Detection direction

  • Start with identity-led correlation: privileged logons, domain replication requests, WinRM sessions, cloud sign-ins, cloud API activity, and changes to cloud roles or credentials should be reviewed together.
  • Tune administrative-tool detections carefully. Net, Nltest, Tasklist, PowerShell, WinRM, and cloud administration interfaces are legitimate, so detection should emphasize unusual user, host, time, scope, privilege level, or sequence of activity.
  • Validate visibility for cloud persistence paths, especially new credentials on applications/service principals and unexpected privileged role assignments.
  • Hunt for discovery-to-lateral-movement chains: account enumeration, process/system discovery, credential access, remote execution, and then data synchronization or ransomware tooling.
  • Use relationship-driven tool context, but avoid relying only on static indicators. Commodity and open-source tools can be renamed, packed, or used legitimately by administrators.

Mitigation priorities

  • Prioritize privileged identity hardening across Active Directory and cloud tenants, including least privilege, review of privileged groups/roles, and monitoring of role and credential changes.
  • Reduce unnecessary remote administration exposure by governing WinRM and administrative pathways, with strong authentication and logging for authorized use.
  • Improve cloud security posture by reviewing service principals/applications, added credentials, privileged role assignments, and API access patterns.
  • Strengthen endpoint controls and logging for PowerShell, scheduled tasks, service/task masquerading, suspicious packing, and known dual-use tooling.
  • Prepare ransomware response playbooks that include identity containment, cloud session/token review, domain controller protection, data movement investigation, and recovery decision points.
Additional notes and limits

This take is derived from the official MITRE group description, external references, and supplied relationships. The most important defensive signal is the breadth of related behaviors: ransomware operations using commodity/open-source tooling with relationships spanning credential access, lateral movement, discovery, execution, persistence/privilege escalation, cloud services, and ransomware-associated software. The object itself has no official detection section and no directly specified platforms or tactics, so platform and tactic guidance is based on the related software and techniques only.

ATT&CK does not provide official detection guidance for Storm-0501 in the supplied fields. The group object does not specify platforms or tactics directly. The external references are listed but not independently analyzed beyond the supplied metadata. Local environment architecture, enabled logging, identity design, cloud providers, and approved administrative tool usage are required to determine actual exposure and detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Storm-0501

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.CitationAvertium Storm-0501 Sabbath Ransomware Arcane January 2022CitationMicrosoft Storm-501 Sabbath Ransomware Embargo September 2024CitationMicrosoft Storm-0501 Embargo Ransomware August 2025CitationGoogle Mandiant Storm-0501 Sabbath Ransomware November 2021

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
ccdd8b9ffe35a2ea...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.