FORENSIA

THREAT_ACTOR · G1053

Storm-0501

Also known as: Storm-0501

Profile

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.

MITRE ATT&CK ↗

Techniques

42 ATT&CK techniques attributed to this actor.

Software

8 malware/tools attributed to this actor.

NetTasklistCobalt StrikeImpacketNltestAADInternalsRcloneEmbargo

Related corpus activity

9,221 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Storm-0501.

IndicatorTypeFamilySevSrc
cve-2026-3102cve853
cve-2026-1969cve851
cve-2013-3307cve852
cve-2014-2321cve851
cve-2025-2492cve852
cve-2021-29441cve851
cve-2025-0921cve852
cve-2021-27076cve851
cve-2016-15047cve854
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2022-47945cve851
cve-2025-66478cve852
cve-2016-5681cve852
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-68670cve852
cve-2025-34054cve854
cve-2024-1781cve851
cve-2025-23304cve852
cve-2023-44976cveransomware852
cve-2020-17456cve851
cve-2020-22653cve852
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 9,221.