THREAT_ACTOR · G1053
Storm-0501
Also known as: Storm-0501
Profile
Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.
MITRE ATT&CK ↗Techniques
42 ATT&CK techniques attributed to this actor.
T1003 OS Credential DumpingT1003.006 DCSyncT1021.006 Windows Remote ManagementT1021.007 Cloud ServicesT1027.002 Software PackingT1036.004 Masquerade Task or ServiceT1053.005 Scheduled TaskT1057 Process DiscoveryT1059.001 PowerShellT1059.009 Cloud APIT1078.004 Cloud AccountsT1082 System Information DiscoveryT1087.002 Domain AccountT1087.004 Cloud AccountT1098.001 Additional Cloud CredentialsT1098.003 Additional Cloud RolesT1110 Brute ForceT1190 Exploit Public-Facing ApplicationT1218.010 Regsvr32T1218.011 Rundll32T1219.002 Remote Desktop SoftwareT1482 Domain Trust DiscoveryT1484.001 Group Policy ModificationT1484.002 Trust ModificationT1485 Data DestructionT1486 Data Encrypted for ImpactT1490 Inhibit System RecoveryT1518.001 Security Software DiscoveryT1526 Cloud Service DiscoveryT1530 Data from Cloud StorageT1537 Transfer Data to Cloud AccountT1552.004 Private KeysT1555.005 Password ManagersT1555.006 Cloud Secrets Management StoresT1556.009 Conditional Access PoliciesT1567.002 Exfiltration to Cloud StorageT1578.003 Delete Cloud InstanceT1580 Cloud Infrastructure DiscoveryT1587.003 Digital CertificatesT1588.006 VulnerabilitiesT1614.001 System Language DiscoveryT1657 Financial Theft
Software
8 malware/tools attributed to this actor.
NetTasklistCobalt StrikeImpacketNltestAADInternalsRcloneEmbargo
Related corpus activity
9,221 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Storm-0501.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,221.