Storm-0501, a financially driven threat actor, has been seen honing its strategies to launch extortion and data exfiltration assaults against cloud environments.
The Microsoft Threat Intelligence team stated in a report shared with The Hacker News that cloud-based ransomware introduces a fundamental shift from traditional on-premises ransomware, where the threat actor usually uses malware to encrypt important files across endpoints within the compromised network and then bargains for a decryption key.
Without using conventional malware distribution, Storm-0501 quickly exfiltrates vast amounts of data, destroys data and backups within the victim environment, and demands ransom by utilizing cloud-native capabilities.
Microsoft first reported on Storm-0501 nearly a year ago. It described the hybrid cloud ransomware attacks that targeted the U.S. government read more about Storm-0501 Exploits Entra ID to Exfiltrate and Delete Azure Data in Hybrid Cloud Attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
