Hybrid cloud environments are under threat as a new threat actor – Storm-0501 – was observed by Microsoft.
In an advisory, Microsoft detailed a novel method of attack performed by the group across multiple sectors in the US, including government, manufacturing, transportation, and law enforcement.
Compromising hybrid cloud environments, the group performed lateral movement from on-premises cloud environments, resulting to data exfiltration, credential theft, ransomware deployment, tampering, and backdoor access.
“Storm-0501 is a financially motivated cyber-criminal group that uses commodity and open-source tools to conduct ransomware operations,” the advisory said.
The group has been active since 2021, and started out targeting US school districts. Since then, the attacks have been mostly opportunistic, operating as a ransomware-as-a-service firm, deploying ransomware payloads created by other threat actors including major hitters such as LockBit and BlackCat.
According to Microsoft, Strom-0501 is the latest threat actor on the scene exploiting weak credential and accounts to maneuver from on-premises to cloud environments.
“They stole credentials and used them to gain control of the network, eventually creating persistent backdoor access to the cloud environment and deploying ransomware to the on-premises,” the advisory said.
“Microsoft previously observed threat actors such as Octo Tempest and Manatee Tempest targeting both on-premises and cloud environments and exploiting the interfaces between the environments to achieve their goals.”
Recommended reading
- New Palo Alto Report Exposes Worrying Cloud Security Gaps
- Failing Cloud Security Could Be ‘Catastrophic’ for Businesses
- Cloud Security Incidents Plaguing Organisations
To initially penetrate on-premise environments, Storm-0501 achieved access leveraging stolen credentials, exploiting unpatched interfaces and known vulnerabilities.
By exploiting the admin privileges on the compromised devices, the threat actors then attempted to get more access to sensitive data and other environments.
Microsoft noted that Strom-0501’s most recent campaign saw the group use stolen credentials to move laterally from the on-premises to the cloud environment and establish access to the network through a backdoor.





