Storm-0501 — Ransomware Profile
Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.Tools & malware
- AADInternals Credential Harvesting
- Cobalt Strike Adversary Simulation
- Embargo Ransomware
- Impacket Network Toolkit
- Net Network Reconnaissance
- Nltest Network Reconnaissance
- Rclone Exfiltration Tool
- Tasklist Discovery
Vendor research
- An In-Depth Look at Ransomware Gang, Sabbath Avertium
- An In-Depth Look at Ransomware Gang, Sabbath Avertium
- Storm-0501: Ransomware attacks expanding to hybrid cloud environments Microsoft
- Storm-0501’s evolving techniques lead to cloud-based ransomware Microsoft
- Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again Google