ATT&CKReferencesMicrosoft Storm-0501 Embargo Ransomware August 2025

Microsoft Storm-0501 Embargo Ransomware August 2025

Microsoft Threat Intelligence. (2025, August 27). Storm-0501’s evolving techniques lead to cloud-based ransomware. Retrieved October 19, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1003.006
DCSync
GroupStorm-0501

Storm-0501 has utilized DCSync to extract credentials from victims.

T1021.006
Windows Remote Management
GroupStorm-0501

Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution.

T1021.007
Cloud Services
GroupStorm-0501

Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment.

T1059.001
PowerShell
GroupStorm-0501

Storm-0501 has leveraged PowerShell to execute commands and scripts.

T1059.009
Cloud API
GroupStorm-0501

Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments.

T1078.004
Cloud Accounts
GroupStorm-0501

Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment.

T1087.004
Cloud Account
GroupStorm-0501

Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound.

T1098.001
Additional Cloud Credentials
GroupStorm-0501

Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method.

T1098.003
Additional Cloud Roles
GroupStorm-0501

Storm-0501 has elevated their access to Azure resources using `Microsoft.Authorization/elevateAccess/action` and `Microsoft.Authorization/roleAssignments/write` operations to gain User Access Administrator and Owner Azure roles over the victims’ Azure subscriptions.

T1484.002
Trust Modification
GroupStorm-0501

Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use.

T1485
Data Destruction
GroupStorm-0501

Storm-0501 has destroyed data and backup files.

T1486
Data Encrypted for Impact
GroupStorm-0501

Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware.

T1490
Inhibit System Recovery
GroupStorm-0501

Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`,
`Microsoft.Compute/restorePointCollections/delete`,
`Microsoft.Storage/storageAccounts/delete`, and
`Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete`.

T1518.001
Security Software Discovery
GroupStorm-0501

Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`.

T1526
Cloud Service Discovery
GroupStorm-0501

Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies.

T1530
Data from Cloud Storage
GroupStorm-0501

Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration.

T1537
Transfer Data to Cloud Account
GroupStorm-0501

Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI.

T1552.004
Private Keys
GroupStorm-0501

Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation.

T1555.006
Cloud Secrets Management Stores
GroupStorm-0501

Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`.

T1556.009
Conditional Access Policies
GroupStorm-0501

Storm-0501 has registered their own MFA method, and leveraged a victim hybrid joined server to circumvent Conditional Access Policies.

T1567.002
Exfiltration to Cloud Storage
GroupStorm-0501

Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI).

T1578.003
Delete Cloud Instance
GroupStorm-0501

Storm-0501 has conducted mass deletion of cloud data stores and resources from Azure subscriptions.

T1580
Cloud Infrastructure Discovery
GroupStorm-0501

Storm-0501 has enumerated compromised cloud environments to identify critical assets, data stores, and back resources.

T1657
Financial Theft
GroupStorm-0501

Storm-0501 has engaged in double-extortion ransomware, exfiltrating data and directly contacting victims when the primary organization refuses to pay along with posting data on their data leak sites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.