HomeSecurityStorm-0501: New ransomware attacks targeting the cloud

Storm-0501: New ransomware attacks targeting the cloud

The financially motivated Storm-0501 is improving its tactics to conduct data exfiltration and extortion targeting environments cloud.

Storm-0501 cloud ransomware

“ Traditional ransomware relies on local installations, where the threat actor typically deploys malware to encrypt critical files on endpoints within the compromised network and then negotiates for a decryption key. In contrast, cloud-based ransomware introduces a fundamental change ,” the Microsoft Threat Intelligence team said in a report shared with The Hacker News.

“Leveraging the power of the cloud, Storm-0501 rapidly extracts large volumes of data, destroys data and backups environment victim's ransom – all without relying on traditional malware development.“.

Storm-0501 was first documented by Microsoft nearly a year ago. The company had described hybrid cloud ransomwaretargeting organizations in the government, industry, transportation, and law enforcement sectors in the U.S. Threat actors had migrated from on-premises installations to the cloud for subsequent data extraction, credential theft, and ransomware deployment.

See also: New Zip Slip Vulnerability: Exploited When Unzipping Files

It is estimated that the Storm-0501 group has been active since 2021 and has operated as a ransomware-as-a-service (RaaS) affiliate, delivering various ransomware payloads, including Sabbath, Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo.

“Storm-0501 continues to demonstrate its ability to move between on-premises and cloud environments, demonstrating how threat actors are adapting as hybrid cloud adoption increases,” the company said. “They are looking for unmanaged devices and vulnerabilities in hybrid cloud environments to evade detection and escalate privileges in the cloud.”

Storm-0501: Chain of infection

Typical attack chains involve the threat actor exploiting initial access to achieve privilege escalation to a domain administrator. This is followed by lateral movement and reconnaissance that allow the attackers to compromise the target's cloud environment, thus initiating a multi-layered sequence that includes persistence, privilege escalation, data extraction, encryption, and extortion.

Storm-0501: New ransomware attacks targeting the cloud

Initial access, according to Microsoft, is achieved through exploits facilitated by access brokers (e.g. Storm-0249 and Storm-0900). They exploit stolen, compromised credentials to log into the target system or exploit various known vulnerabilities for remote code execution on unpatched publicly accessible servers.

See also: Cephalus Ransomware: Exploits RDP for Home Access

In a recent campaign targeting an unnamed large enterprise with multiple subsidiaries, Storm-0501 reportedly conducted reconnaissance before moving laterally through the network using Evil-WinRM. The attackers also performed what is called a DCSync to extract credentials from Active Directory by simulating the behavior of a domain controller.

“Using their access to the Active Directory environment, they moved between Active Directory domains and eventually moved laterally to compromise a second Entra Connect server, connected to a different Entra ID tenant and Active Directory domain,” Microsoft said.

“The threat actor exported the Directory Synchronization Account to repeat the reconnaissance process, this time targeting identities and resources in the second tenant“.

These efforts ultimately allowed Storm-0501 to locate a non-human synced identity with the Global Admin role in Microsoft Entra ID in this tenant (also, there was no MFA protection). This then allowed the attackers to reset the user's password on-premises, causing it to sync with that user's cloud identity using the Entra Connect Sync service.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Armed with the compromised Global Admin, the attackers gain access to the Azure Portalby registering an Entra ID tenant (owned by the threat actor) as a trusted federated domain. This allows the team to create a backdoor to enhance their access.

“After completing the extraction phase, Storm-0501 initiated a mass deletion of Azure resources containing the victim organization’s data, preventing the victim from taking remediation and mitigation measures,” Microsoft said.

Storm-0501: New ransomware attacks targeting the cloud

“After successfully removing and destroying the data in the Azure environment, the threat actor initiated the extortion, where it contacted victims using Microsoft Teams and demanded a ransom.“.

See also: Salesforce Data Theft via Compromised AI Tool

The company said it has implemented a change to Microsoft Entra ID that prevents threat actors from abusing Directory Synchronization Accounts for privilege escalation. It has also released updates to Microsoft Entra Connect (version 2.5.3.0) to support Modern Authentication, allowing customers to configure application-based authentication for improved security.

"It is also important to enable the Trusted Platform Module (TPM) on the Entra Connect Sync server to securely store sensitive credentials and cryptographic keys, mitigating Storm-0501's credential extraction techniques," the tech giant added.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS