Sunturai
Threat report

www.microsoft.com/en-us/security/blog/2025/08/27/storm-0501s-evolving-techniques-lead-to-cloud-based-ransomware

https://www.microsoft.com/en-us/security/blog/2025/08/27/storm-0501s-evolving-techniques-lead-to-cloud-based-ransomware/
Published on
www.microsoft.com

ATT&CK techniques those detections carry

  • T1485Data Destruction
  • T1078Valid Accounts
  • T1078.004Cloud Accounts
  • T1098Account Manipulation
  • T1098.003Additional Cloud Roles
  • T1530Data from Cloud Storage
  • T1489Service Stop
  • T1490Inhibit System Recovery
  • +9 more
Open the original

13 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
AzCopy or Azure Storage Explorer Usage on Unusual HostMedium
Azure RBAC Built-In Administrator Roles AssignedHigh
Entra ID Elevated Access to User Access AdministratorHigh
Entra ID Global Administrator Role AssignedHigh
Entra ID Service Principal with Unusual Source ASNMedium
Azure Storage Account Deletions by UserHigh
Azure Storage Account Deletion by Unusual UserMedium
Azure Compute Snapshot Deletions by UserMedium
Azure Compute Snapshot Deletion by Unusual User and Resource GroupLow
Azure Storage Blob Retrieval via AzCopyMedium
Azure Storage Account Keys Accessed by Privileged UserMedium
Azure Service Principal Sign-In Followed by Arc Cluster Credential AccessMedium
Azure Storage Account Blob Public Access EnabledMedium

Showing 13 of 13

Filter in the catalogue

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice