Storm-0501 is a financially motivated cybercriminal group deploying various ransomware through a RaaS model.
Analyst brief
Storm-0501 is a financially motivated cybercriminal group active since 2021, known for initially targeting US school districts and later adopting a RaaS model to deploy various ransomware strains, including Embargo. They target weakly secured environments, moving laterally from on-premises to cloud infrastructures using stolen credentials and over-privileged accounts. Their key TTPs include exploiting public-facing applications, leveraging tools like Cobalt Strike, Impacket, Rclone, and cloud account manipulation for persistence, collection, and data exfiltration. Defenders should focus on detecting exploitation of public-facing apps, unauthorized addition of cloud roles, and large data transfers to cloud storage.
Storm-0501
unknown
Storm-0501 is a financially motivated cybercriminal group that has been active since 2021, initially targeting US school districts with the Sabbath ransomware and later transitioning to a RaaS model deploying various ransomware strains, including Embargo. The group exploits weak credentials and over-privileged accounts to achieve lateral movement from on-premises environments to cloud infrastructures, establishing persistent backdoor access and deploying ransomware. They have utilized techniques such as credential theft, exploiting vulnerabilities in Zoho ManageEngine and Citrix NetScaler, and employing tools like Cobalt Strike and Rclone for lateral movement and data exfiltration. Storm-0501 has specifically targeted sectors such as government, manufacturing, transportation, and law enforcement in the United States.
Monitor system activity and data modifications to detect data destruction and inhibit system recovery.
FAQ2
What are the main commercial tools used by the Storm-0501 group?+
The group uses tools like Cobalt Strike, Impacket, and Rclone.
What TTPs does Storm-0501 employ that defenders should especially pay attention to?+
Defenders should be vigilant against exploitation of public-facing apps, unauthorized addition of cloud roles, and data exfiltration attempts to cloud storage.