Storm-0501 is a financially motivated ransomware operator tracked by Microsoft and included as a threat group in ATT&CK v18. The actor has conducted hybrid on-premises and cloud intrusions, including operations in multi-tenant Azure environments, and has been associated with deployment of Embargo ransomware. Storm-0501 has also been linked to abuse of Azure encryption scopes to extort victims by rendering Azure Blob Storage data inaccessible through malicious key and encryption-scope manipulation rather than only through traditional endpoint encryption workflows. The group’s operations show a blend of enterprise intrusion tradecraft and cloud-focused post-compromise activity. Reported access and expansion methods include exploitation of public-facing applications, abuse of compromised accounts, use of a victim Global Administrator account lacking MFA enrollment, access to Microsoft Entra Connect in hybrid identity environments, and use of storage account access keys. In cloud environments, Storm-0501 has used AzureHound to enumerate Entra ID tenants and identify relationships, privileges, and attack paths. On Windows systems, Storm-0501 has used native tooling and common offensive frameworks for discovery, execution, credential access, and payload delivery. Observed behaviors include PowerShell execution, regsvr32-based launching of Cobalt Strike Beacon, process discovery with tasklist, endpoint and system discovery with systeminfo, and security software discovery through service queries against Microsoft Defender components. For credential access, the actor has used Impacket SecretsDump to obtain account and password information. For ransomware distribution at scale, Storm-0501 used a scheduled task named SysUpdate deployed through Group Policy Objects to push Embargo ransomware across victim networks. Storm-0501 has demonstrated strong data theft and cloud exfiltration capability. Reported exfiltration methods include use of Rclone, AzCopy, and transfers to MEGA and related cloud storage destinations. The actor has also used self-signed TLS certificates on its infrastructure. Microsoft additionally reported that malware used by Storm-0501 was signed through the Fox Tempest malware-signing-as-a-service operation, indicating overlap with criminal ecosystem services that support defense evasion and payload delivery. Overall, Storm-0501 is best characterized as a ransomware and extortion actor with capabilities spanning initial access, credential theft, reconnaissance, defense evasion, persistence, exfiltration, and post-exploitation across both traditional Windows enterprise networks and Azure-centric cloud estates.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
Initial Access Primary (Storm-0501): Exploitation of known N-day vulnerabilities in internet-facing applications: CVE-2022-47966 (Zoho ManageEngine RCE)
Initial Access Primary (Storm-0501): Exploitation of known N-day vulnerabilities in internet-facing applications: CVE-2023-29300 / CVE-2023-38203 (Adobe ColdFusion)
Initial Access Primary (Storm-0501): Exploitation of known N-day vulnerabilities in internet-facing applications: CVE-2023-29300 / CVE-2023-38203 (Adobe ColdFusion)
Initial Access Primary (Storm-0501): Exploitation of known N-day vulnerabilities in internet-facing applications: CVE-2023-4966 (Citrix NetScaler - "Citrix Bleed")
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
8 more CVEs tied to this actor tracked in Mallory.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Mentioned only in a list of actors tied to ATT&CK T1190.
Abused Azure encryption scopes and Key Vault keys post-compromise to render victim storage data inaccessible and demand ransom.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.