Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0501

Description

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.(Citation: Avertium Storm-0501 Sabbath Ransomware Arcane January 2022)(Citation: Microsoft Storm-501 Sabbath Ransomware Embargo September 2024)(Citation: Microsoft Storm-0501 Embargo Ransomware August 2025)(Citation: Google Mandiant Storm-0501 Sabbath Ransomware November 2021)

AI Analysis

· 1 week ago

Executive Summary

Storm-0501 is a financially motivated cybercriminal group known for using commodity and open-source tools in their ransomware operations. They have been active since 2021 and have associations with several Ransomware-as-a-Service (RaaS) variants including Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware. Their targeting primarily focuses on sectors such as healthcare, education, manufacturing, and retail across North America, Europe, and parts of Asia.

Goals & Targeting

Storm-0501's primary goal is financial gain through ransomware operations. They target sectors with higher organizational resilience, such as healthcare, education, manufacturing, and retail, which often have the resources to pay ransoms but may lack robust cybersecurity measures. The group's targeting of North America, Europe, and parts of Asia reflects their strategic focus on regions with a higher density of potential victims and economic capacity for ransom payments. Their preference for mid-sized organizations likely stems from easier infiltration and lower defensive barriers compared to larger enterprises.

Enhanced Description

Storm-0501 operates with a primary focus on financial gain, utilizing readily available tools and open-source software to carry out their attacks. The group's operations have evolved since its emergence in late 2021, initially under the alias 'Sabbath Ransomware.' They have demonstrated adaptability by affiliating themselves with various ransomware families, indicating a flexible approach to maintaining their criminal activities. Their campaigns often involve sophisticated tactics such as initial phishing or compromised credentials for access, followed by lateral movement within networks using tools like Cobalt Strike. The group has shown a preference for targeting mid-sized organizations, leveraging their lower security posture compared to larger enterprises. Storm-0501's operations have been linked to several high-profile incidents in 2023 and 2024, with notable campaigns focusing on encrypting data while demanding substantial ransoms for decryption keys. Their use of cloud infrastructure and system manipulation techniques suggests an understanding of modern enterprise environments.

Key Capabilities

  • Ransomware-as-a-Service (RaaS) operations
  • Use of commodity tools like Cobalt Strike
  • Spear-phishing campaigns
  • Cloud infrastructure exploitation
  • Data encryption for impact

MITRE ATT&CK Tactics

Credential Access
Defense Evasion
Discovery
Execution
Lateral Movement

ATT&CK Techniques

T1053.005: Scheduled Task
T1490: Inhibit System Recovery
T1087.002: Domain Account
T1003: OS Credential Dumping
T1587.003: Digital Certificates

Software / Tooling

Cobalt Strike
Embargo Ransomware

Campaigns & Victims

Storm-0501 has been involved in numerous campaigns targeting mid-sized organizations, often employing phishing emails with malicious attachments or compromised credentials to gain initial access. Their campaigns typically involve the deployment of ransomware following extensive network enumeration and lateral movement. Notable incidents include attacks on healthcare providers, educational institutions, and manufacturing companies. The group has demonstrated a rapid operational tempo, launching multiple campaigns over short periods, particularly in 2023-2024.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • Use of Cobalt Strike for lateral movement
  • Scheduled task creation and modification
  • Encryption of files across network drives

Recommended Actions

  • Implement robust email filtering solutions to detect phishing attempts
  • Enhance endpoint detection and response capabilities
  • Conduct regular backups of critical systems with offline storage options
  • Monitor for异常scheduled task activity on endpoints
  • Educate employees on identifying spear-phishing emails

Suggested Tags

Ransomware
Financially Motivated
Mid-Sized Organizations
Cloud Infrastructure
Cobalt Strike

Confidence Assessment

High confidence in Storm-0501's operational details and TTPs, based on multiple reports from reputable sources. Limited information on exact campaign timelines and geographic targeting patterns beyond high-level regional focus exists.

ATT&CK Techniques

Credential Access
6 techniques
Defense impairment
4 techniques
Discovery
9 techniques
Impact
4 techniques
Stealth
5 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Avertium Storm-0501 Sabbath Ransomware Arcane January 2022 — Avertium. (2022, January 11). An In-Depth Look at Ransomware Gang, Sabbath. Retrieved October 19, 2025.
  2. Microsoft Storm-501 Sabbath Ransomware Embargo September 2024 — Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.
  3. Microsoft Storm-0501 Embargo Ransomware August 2025 — Microsoft Threat Intelligence. (2025, August 27). Storm-0501’s evolving techniques lead to cloud-based ransomware. Retrieved October 19, 2025.
  4. Google Mandiant Storm-0501 Sabbath Ransomware November 2021 — Tyler McLellan, Brandan Schondorfer. (2021, November 29). Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again. Retrieved October 19, 2025.

Intel Summary

42

Techniques

3

Tools

0

Campaigns

0

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Financially Motivated
Mid-Sized Organizations
Cloud Infrastructure
Cobalt Strike

Details

MITRE ID
G1053
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--7b404cd0-3ae9-41d4-90c0-023793d35d97
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.