Storm-0506 is a financially motivated ransomware threat actor tracked by Microsoft and associated with Black Basta ransomware deployment. Its documented victims include an engineering firm in North America. The actor conducts human-operated intrusions involving credential theft, privilege escalation, lateral movement, persistence, and ransomware deployment against Windows systems and VMware ESXi virtualization infrastructure. Storm-0506 is distinct from the broader Black Basta operation and from initial access brokers that deliver access to its operators. In a documented 2024 intrusion, Storm-0506 obtained initial access through a Qakbot infection and exploited the Windows Common Log File System vulnerability CVE-2023-28252 to elevate privileges. It used Cobalt Strike and Pypykatz to steal domain-administrator credentials and moved laterally to multiple domain controllers. Persistence involved custom tools and SystemBC implants. The actor also attempted to brute-force Remote Desktop Protocol connections and tamper with Microsoft Defender Antivirus. Storm-0506 exploited CVE-2024-37085 by creating an Active Directory group that domain-joined ESXi hosts recognized as privileged and adding an attacker-controlled account. This granted administrative access to the hypervisors, enabling filesystem encryption and disruption of hosted virtual machines. It also used PsExec to attempt ransomware deployment against devices outside the ESXi environment. Separately, Storm-0506 deployed Black Basta following an infection chain involving Storm-0569's BATLOADER and Cobalt Strike, demonstrating operational handoffs from an initial access broker.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named “ESX Admins” to have full administrative access by default.
The threat actor gained initial access to the organization via Qakbot infection, followed by the exploitation of a Windows CLFS vulnerability (CVE-2023-28252) to elevate their privileges on affected devices.
A newly disclosed vulnerability, CVE-2025-53770, affecting on-premises Microsoft SharePoint Server, enables unauthenticated remote code execution (RCE) through insecure deserialization of untrusted data... Microsoft has confirmed that public exploits are available and actively being used by threat actors.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only as a source/reference, not discussed as part of the event itself.
Activity cluster observed using CVE-2024-37085 in an ESXi/AD context to enable deployment of Black Basta ransomware.
Cited as a possible actor based on historical TTPs; previously associated (per the article) with targeting enterprise collaboration tools in espionage-oriented activity, and potentially relevant to SharePoint exploitation of CVE-2025-53770.
Storm-0506 is involved in ransomware campaigns exploiting VMware ESXi authentication bypass vulnerabilities to deploy Akira and Black Basta ransomware, leading to data theft and operational disruption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.