THREATOPS Actor Dossier
LIVE ← Dashboard

Storm-0501

G10531 reports
aliases · Storm-0501
Export dossier:
1
Reports
1
Techniques
1
Tactics
1
Countries
100%
Hunt coverage
1
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1589.001 (Credentials).
  • Primary targeting: US.
  • Activity declining: 0 report(s) in last 30d vs 1 prior (-100%).
  • Hunt coverage 100% of 1 observed techniques (0 gap(s)).
  • Assessment confidence: medium (60).

Activity & trend

DecliningLast 30d: 0 vs 1 prior (-100%)· first reported 2026-08-17 · last 2026-08-17
0
7d
0
30d
1
90d
1
All
0.1
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

Targeting lost
US

Overview

Analyst triage
Intelligence summary

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.(Citation: Avertium Storm-0501 Sabbath Ransomware Arcane January 2022)(Citation: Microsoft Storm-501 Sabbath Ransomware Embargo September 2024)(Citation: Microsoft Storm-0501 Embargo Ransomware August 2025)(Citation: Google Mandiant Storm-0501 Sabbath Ransomware November 2021)

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected