Storm-0501
G10531 reportsAnalyst assessment — key judgments
- Signature techniques: T1589.001 (Credentials).
- Primary targeting: US.
- Activity declining: 0 report(s) in last 30d vs 1 prior (-100%).
- Hunt coverage 100% of 1 observed techniques (0 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
Movement — last 30 days
Overview
Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.(Citation: Avertium Storm-0501 Sabbath Ransomware Arcane January 2022)(Citation: Microsoft Storm-501 Sabbath Ransomware Embargo September 2024)(Citation: Microsoft Storm-0501 Embargo Ransomware August 2025)(Citation: Google Mandiant Storm-0501 Sabbath Ransomware November 2021)
ATT&CK technique matrix
- T1589.001 · Credentialsconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|