ZeroHour
Tenable Blogpublished ()ingested Clément Notin

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

mediumThreat actor exploited in the wildimportance 55
AI summary · glm-5.3-flash

Tenable details ransomware group Storm-0501's Azure tenant-hijacking tactics and how its cloud detection and response identifies them.

Tenable's blog describes how cybercrime group Storm-0501 conducts cloud-first ransomware campaigns against Azure environments. The group has shifted from endpoint encryption to total hijacking of cloud tenants and systematically neutralizes resource locks, immutability policies, and backups. Tenable outlines its One Cloud Exposure detections, using AI-powered threat stories and precision alerts, to expose these TTPs early.

  • Storm-0501 shifts from endpoint encryption to full Azure tenant takeover
  • Group neutralizes resource locks, immutability policies, and backups
  • Detection of these configuration changes enables early intervention
  • Tenable One provides cloud detection and response for these campaigns
Full article

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts. Key takeaways Storm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants. Storm-0501 systematically neutralizes resource locks, immutability policies, and backups, making the detection of these configuration changes critical for early intervention. Detecting modern campaigns requires moving beyond…

This source does not provide full text. Read it at tenable.com.