About this actor
[Storm-0501](https://attack.mitre.org/groups/G1053) is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. [Storm-0501](https://attack.mitre.org/groups/G1053) has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, [BlackCat](https://attack.mitre.org/software/S1068), Hunters International, [LockBit 3.0](https://attack.mitre.org/software/S1202), and [Embargo](https://attack.mitre.org/software/S1247) ransomware.(Citation: Avertium Storm-0501 Sabbath Ransomware Arcane January 2022)(Citation: Microsoft Storm-501 Sabbath Ransomware Embargo September 2024)(Citation: Microsoft Storm-0501 Embargo Ransomware August 2025)(Citation: Google Mandiant Storm-0501 Sabbath Ransomware November 2021)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 62 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.006DCSync ↗T1021Remote Services ↗T1021.006Windows Remote Management ↗T1021.007Cloud Services ↗T1027Obfuscated Files or Information ↗T1027.002Software Packing ↗T1036Masquerading ↗T1036.004Masquerade Task or Service ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.009Cloud API ↗T1078Valid Accounts ↗T1078.004Cloud Accounts ↗T1082System Information Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1087.004Cloud Account ↗T1098Account Manipulation ↗T1098.001Additional Cloud Credentials ↗T1098.003Additional Cloud Roles ↗T1110Brute Force ↗T1190Exploit Public-Facing Application ↗T1218System Binary Proxy Execution ↗T1218.010Regsvr32 ↗T1218.011Rundll32 ↗T1219Remote Access Tools ↗T1219.002Remote Desktop Software ↗T1482Domain Trust Discovery ↗T1484Domain or Tenant Policy Modification ↗T1484.001Group Policy Modification ↗T1484.002Trust Modification ↗T1485Data Destruction ↗T1486Data Encrypted for Impact ↗T1490Inhibit System Recovery ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1526Cloud Service Discovery ↗T1530Data from Cloud Storage ↗T1537Transfer Data to Cloud Account ↗T1552Unsecured Credentials ↗T1552.004Private Keys ↗T1555Credentials from Password Stores ↗T1555.005Password Managers ↗T1555.006Cloud Secrets Management Stores ↗T1556Modify Authentication Process ↗T1556.009Conditional Access Policies ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1578Modify Cloud Compute Infrastructure ↗T1578.003Delete Cloud Instance ↗T1580Cloud Infrastructure Discovery ↗T1587Develop Capabilities ↗T1587.003Digital Certificates ↗T1588Obtain Capabilities ↗T1588.006Vulnerabilities ↗T1614System Location Discovery ↗T1614.001System Language Discovery ↗T1657Financial Theft ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 40 / 62 | 65% |
AC-3 | 38 / 62 | 61% |
AC-6 | 36 / 62 | 58% |
AC-2 | 35 / 62 | 56% |
CM-6 | 31 / 62 | 50% |
IA-2 | 30 / 62 | 48% |
AC-5 | 28 / 62 | 45% |
CM-7 | 27 / 62 | 44% |
CM-2 | 25 / 62 | 40% |
CM-5 | 23 / 62 | 37% |
SI-7 | 21 / 62 | 34% |
CA-7 | 19 / 62 | 31% |
IA-5 | 16 / 62 | 26% |
AC-4 | 15 / 62 | 24% |
RA-5 | 15 / 62 | 24% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Scattered Spider 0.27
- SolarWinds Compromise 0.22
- VOID MANTICORE 0.21
- BlackByte 0.20
- C0027 0.20