Storm-0501 is a financially motivated cybercriminal threat actor active since 2021 that conducts ransomware and extortion operations across on-premises and hybrid-cloud environments. Also labeled storm_0501_ransomware, it is a publicly tracked affiliate of the Embargo ransomware-as-a-service operation, rather than a synonymous name for the operation itself. It has previously deployed Sabbath, Hive, BlackCat, Hunters International, and LockBit 3.0 ransomware. Its operations combine credential compromise, lateral movement, data theft, and ransomware deployment. Storm-0501 gains initial access through exploitation of known vulnerabilities in internet-facing applications, including Zoho ManageEngine, Citrix NetScaler, and Adobe ColdFusion. It conducts Active Directory, host, and security-software discovery and obtains credentials through Impacket SecretsDump, DCSync, KeePass credential theft, and brute-force activity. Its tooling includes Cobalt Strike, PowerShell remoting, Evil-WinRM, and legitimate remote-management applications. It abuses trusted Windows utilities for payload execution and has distributed Embargo ransomware through Group Policy–registered scheduled tasks. It also has used malware signed through a fraudulent code-signing service. Data exfiltration tooling includes Rclone, MegaSync, and AzCopy. The actor has expanded into Microsoft Azure and Entra ID environments by compromising hybrid identity infrastructure and abusing privileged accounts. Its cloud operations include AzureHound tenant enumeration, privileged-account password resets, registration of attacker-controlled MFA methods, and federated-domain backdoors created with AADInternals. It accesses cloud storage credentials and performs cloud-to-cloud data theft. Storm-0501 has also abused Azure encryption scopes and Key Vault key deletion to make victim data inaccessible and demand ransom; Key Vault soft-delete protections have preserved recoverability in observed attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
22 malware families attributed to this actor across reporting.
17 additional families tracked in Mallory.
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
Storm-0501 exploits unpatched Zoho ManageEngine (CVE-2022-47966) as an initial-access vector.
The profile lists CVE-2023-29300 / CVE-2023-38203 as Adobe ColdFusion vulnerabilities used as known N-day initial-access vectors by Storm-0501; its infection chain specifically cites CVE-2023-29300.
The profile lists CVE-2023-29300 / CVE-2023-38203 as Adobe ColdFusion vulnerabilities exploited as known N-day initial-access vectors by Storm-0501.
The profile identifies CVE-2023-4966 (Citrix NetScaler, "Citrix Bleed") as a known N-day vulnerability exploited by Storm-0501 for initial access.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
8 more CVEs tied to this actor tracked in Mallory.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cited as combining Rclone, MegaSync, and AzCopy CLI for cloud-based data exfiltration.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Mentioned only in a list of actors tied to ATT&CK T1190.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.