Saturday , April 19 2025
Cloud

Microsoft warns Storm-0501 targets hybrid cloud environments

Microsoft cybersecurity researchers found that the “Storm-0501” ransomware group is targeting hybrid cloud environments.

Storm-0501 Attacking Cloud Environments:

CVE-2025-2492
ASUS warns of critical auth bypass flaw in routers

Hackers can exploit a vulnerability in Asus routers to execute unauthorized functions. This serious issue, rated 9.2 out of 10,...
Read More
CVE-2025-2492  ASUS warns of critical auth bypass flaw in routers

16,000+ Fortinet devices compromised with symlink backdoor, Mostly in Asia

According to Shadowserver Foundation around 17,000 Fortinet devices worldwide have been compromised using a new technique called "symlink". This number...
Read More
16,000+  Fortinet devices compromised with symlink backdoor, Mostly in Asia

Patch now! Critical Erlang/OTP SSH Vuln Allows UCE

A critical security flaw has been found in the Erlang/Open Telecom Platform (OTP) SSH implementation, allowing an attacker to run...
Read More
Patch now! Critical Erlang/OTP SSH Vuln Allows UCE

CISA warns of increasing risk tied to Oracle legacy Cloud leak

On Wednesday, CISA alerted about increased breach risks due to the earlier compromise of legacy Oracle Cloud servers, emphasizing the...
Read More
CISA warns of increasing risk tied to Oracle legacy Cloud leak

CVE-2025-20236
Cisco Patches Unauthenticated RCE Flaw in Webex App

Cisco issued a security advisory about a serious vulnerability in its Webex App that allows unauthenticated remote code execution (RCE)...
Read More
CVE-2025-20236  Cisco Patches Unauthenticated RCE Flaw in Webex App

Apple released emergency security updates for 2 zero-day vulns

On Wednesday, Apple released urgent operating system updates to address two security vulnerabilities that had already been exploited in highly...
Read More
Apple released emergency security updates for 2 zero-day vulns

Oracle Released Patched for 378 flaws for April 2025

On April 15, 2025, Oracle released a Critical Patch Update for 378 flaws for its products. The patch update covers...
Read More
Oracle Released Patched for 378 flaws for April 2025

CVE-2025-24054
Hackers Exploiting NTLM Spoofing Windows Vuln the in Wild

Check Point Research warns of the active exploitation of a new vulnerability, CVE-2025-24054, which lets hackers leak NTLMv2-SSP hashes using...
Read More
CVE-2025-24054  Hackers Exploiting NTLM Spoofing Windows Vuln the in Wild

Bengaluru firm got ransomware attack, Hacker demanded $70,000

Bengaluru's Whiteboard Technologies Pvt Ltd was hit by a ransomware attack, with hackers demanding a ransom of up to $70,000...
Read More
Bengaluru firm got ransomware attack, Hacker demanded $70,000

MITRE warns: U.S. Govt. Funding for MITRE’s CVE Ends Today

MITRE Vice President Yosry Barsoum warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness...
Read More
MITRE warns: U.S. Govt. Funding for MITRE’s CVE Ends Today

Storm-0501 is a ‘financially motivated’ threat group that has launched a sophisticated ‘multi-stage attack’ targeting “hybrid cloud environments” across various ‘U.S. sectors’ and ‘critical infrastructure.’

The group exploited vulnerabilities in Zoho ManageEngine, Citrix NetScaler, and ColdFusion 2016 to access on-premises systems.

Then for lateral movement and credential access, they used tools such as “Impacket’s SecretsDump” and “Cobalt Strike.”

The attackers pivoted from “on-premises” to “cloud environments” by compromising “Microsoft Entra Connect Sync” accounts, which allows them to manipulate the “Microsoft Entra ID” (formerly Azure AD) identities.

They used ‘Rclone’ disguised as ‘Windows binaries’ to exfiltrate data and deployed various ransomware types, including “Hive,” “BlackCat,” and “LockBit.”

The actions of Storm-0501 emphasize the increasing security risks in hybrid cloud environments, showing the need for strong protections in both on-premises and cloud systems.

This group targets “accounts with disabled MFA and Global Administrator roles.”

The attackers use various techniques to create persistent backdoors and here below:

Password synchronization exploitation
Cloud session hijacking
Leveraging the AADInternals PowerShell module

They can change managed domains to federated ones, alter SAML tokens, and skip MFA.

In some cases, the threat actors deploy “Embargo ransomware,” it’s a Rust-based strain that makes use of advanced encryption and it’s distributed via Group “Policy Objects (GPOs)” and “scheduled tasks.”

The ransomware encrypts files, changes the extensions to “.partial,” “.564ba1,” or “.embargo,” and employs double extortion tactics.

Mitigations:

Here below we have mentioned all the mitigations:-

Use the least privilege and audit privileged accounts.
Enable Conditional Access for device compliance and trusted IPs.
Restrict Entra ID sync accounts from untrusted IPs.
Use phishing-resistant authentication for critical apps.
Follow best practices for Active Directory Federation Services.
Refer to Azure AD security best practices.
Turn on Defender for Cloud Apps alerts.
Prevent bypassing Entra MFA when federated.
Block sign-ins to non-federated domains.
Enable Entra ID protection for risky sign-ins.
Use tamper protection to secure services.
Block unapproved IT tools with AppLocker.
Run EDR in block mode for extra protection.
Enable automated investigation in Defender.

Octo2: European Banks Already Under Attack by New Malware varient

Check Also

Ivanti

Hackers Exploit Ivanti VPN Vulns 12 Countries to Infiltrate Multiple Orgs

In late March, TeamT5 found that a China-linked APT group exploited a critical vulnerability in …

Leave a Reply

Your email address will not be published. Required fields are marked *