Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics

Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics

First seen 17 Aug 2026, 15:50 UTC Tenableattack.mitre.orgwww.microsoft.com 82% similarity 74.0

Article Content

Browse articles
ThreatCluster

Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their tactics to target cloud environments, specifically Azure, by hijacking high-privilege administrative identities and weaponizing native cloud tools. The group has utilized tools like ADRecon.ps1 and Azurehound for reconnaissance and has executed brute force attacks to obtain credentials. They have also leveraged PowerShell and Cloud CLI for command execution and data exfiltration. Storm-0501's operations have included destroying data backups and encrypting files, leading to significant impacts on victim organizations. Current detection capabilities, such as those from Tenable One, are essential for identifying and mitigating these sophisticated attacks.

Key Points: • Storm-0501 uses Ransomware-as-a-Service (RaaS) to conduct Azure-based ransomware operations. • The group employs advanced tactics, including hijacking administrative identities and using cloud-native tools. • Detection solutions like Tenable One are crucial for identifying and responding to Storm-0501's tactics.

ThreatCluster AI How this analysis works

Timeline

2023-01-18
CVE-2022-47966 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-10-10
CVE-2023-4966 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-08
CVE-2023-29300 added to CISA KEV
CISA confirmed active exploitation of CVE-2023-29300, a vulnerability affecting Azure services.
Tenable
2024-01-08
CVE-2023-38203 added to CISA KEV
CISA reported active exploitation of CVE-2023-38203, impacting cloud environments.
Tenable
2026-08-17
Storm-0501's tactics detailed
Tenable One outlines Storm-0501's sophisticated tactics and their impact on Azure environments.
Tenable
2026-08-17
Storm-0501 conducts ransomware operations
The group has been confirmed to use various RaaS variants to encrypt files and exfiltrate data from Azure.
attack.mitre.org

Community

Browse all →