Microsoft has observed that Storm-0501 hackers have turned to ransomware attacks targeting hybrid cloud environments in organizations in the government, construction, transportation , and law enforcement sectors.

Multi-stage attacks target hybrid cloud environments and perform lateral movement from on-premises to cloud, resulting in data exfiltration, credential theft, compromise, and ultimately ransomware deployment.
“Storm-0501 is a financially motivated group that uses open source tools to conduct ransomware operations,” Microsoft researchers say.
The hackers have been active since 2021. They started targeting educational entities with the Sabbath ransomware (54bb47h). However, they later started operating as affiliates of ransomware groups and distributing various ransomware payloads (e.g. Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware).
See also: New Linux variant of Mallox ransomware is based on Kryptina code
Storm-0501 hackers often exploit weak credentials and over-privileged accounts to reach cloud infrastructure and deploy ransomware. They can also exploit vulnerabilities in unpatched, exposed systems.
This initial access allows attackers to discover and define useful assets to begin intelligence gathering and Active Directory reconnaissance. This is followed by the deployment of remote monitoring and management (RMM) tools such as AnyDesk (for persistence).
"The attackers exploited administrator privileges on the local devices they compromised during initial access and attempted to gain access to more accounts within the network through various methods," Microsoft said.
Researchers observed that the Storm-0501 hackers primarily used module SecretsDump 's , which extracts credentials over the network.
The compromised credentials are then used to access even more devices and extract additional credentials. Attackers are ultimately able to gain access to sensitive files, steal KeePass secrets, and perform brute-force attacks to obtain credentials for specific accounts.
Additionally, Microsoft saw that Storm-0501 hackers were using Cobalt Strike to move around the network using compromised credentials. Data extraction from on-premises environments is achieved via Rclone, which transfers the data to the public cloud storage service MegaSync.
See also: Vanilla Tempest hackers target healthcare organizations with INC ransomware

Hackers are also creating persistent backdoor access to the cloud environment and deploying ransomware on premises. Storm-0501 hackers are the third group we see targeting hybrid cloud environments, following Octo Tempest and Manatee Tempest.
“The threat actor used credentials, specifically the Microsoft Entra ID (formerly Azure AD), stolen earlier in the attack, to move from the on-premises installation to the cloud environment and establish persistent access to the target network via a backdoor,” Microsoft said.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The attack culminates with the deployment of Embargo ransomware.
“Operating under the RaaS model, the ransomware group behind Embargo allows affiliates, such as Storm-0501, to use its platform to launch attacks in exchange for a share of the ransom,” Microsoft said.
“Embargo affiliates use double-blackmail, where they first encrypt a victim's files and threaten to leak stolen sensitive data unless a ransom is paid.“.
Ransomware protection
Back up your data: One of the most effective ways to protect yourself from a attack is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.
See also: Ransomware gangs abuse Azure Storage Explorer
Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware.
Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.

Use antivirus software: Installing reputable antivirus software on your devices can help you detect and prevent attacks . Be sure to update your antivirus software to ensure it is equipped to handle new threats.
Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.
Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.
Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.
Source: thehackernews.com
