Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1053
MITRE ATT&CK Group

Storm-0501 (G1053)

ShareXLinkedInRedditHN

[Storm-0501](https://attack.mitre.org/groups/G1053) is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. [Storm-0501](https://attack.mitre.org/groups/G1053) has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, [BlackCat](https://attack.mitre.org/software/S1068), Hunters International, [LockBit 3.0](https://attack.mitre.org/software/S1202), and [Embargo](https://attack.mitre.org/software/S1247) ransomware.(Citation: Avertium Storm-0501 Sabbath Ransomware Arcane January 2022)(Citation: Microsoft Storm-501 Sabbath Ransomware Embargo September 2024)(Citation: Microsoft Storm-0501 Embargo Ransomware August 2025)(Citation: Google Mandiant Storm-0501 Sabbath Ransomware November 2021)

▪Techniques used (42)

T1219.002Remote Desktop SoftwareT1537Transfer Data to Cloud AccountT1490Inhibit System RecoveryT1484.001Group Policy ModificationT1530Data from Cloud StorageT1059.001PowerShellT1485Data DestructionT1053.005Scheduled TaskT1087.004Cloud AccountT1003.006DCSyncT1526Cloud Service DiscoveryT1567.002Exfiltration to Cloud StorageT1059.009Cloud APIT1021.007Cloud ServicesT1021.006Windows Remote ManagementT1190Exploit Public-Facing ApplicationT1057Process DiscoveryT1518.001Security Software DiscoveryT1486Data Encrypted for ImpactT1657Financial TheftT1078.004Cloud AccountsT1218.010Regsvr32T1555.006Cloud Secrets Management StoresT1555.005Password ManagersT1484.002Trust ModificationT1580Cloud Infrastructure DiscoveryT1482Domain Trust DiscoveryT1578.003Delete Cloud InstanceT1082System Information DiscoveryT1027.002Software PackingT1614.001System Language DiscoveryT1552.004Private KeysT1036.004Masquerade Task or ServiceT1098.003Additional Cloud RolesT1087.002Domain AccountT1218.011Rundll32T1587.003Digital CertificatesT1588.006VulnerabilitiesT1556.009Conditional Access PoliciesT1003OS Credential DumpingT1110Brute ForceT1098.001Additional Cloud Credentials

▪Software used (8)

S0357ImpackettoolS0057TasklisttoolS0154Cobalt StrikemalwareS1247EmbargomalwareS1040RclonetoolS0359NltesttoolS0039NettoolS0677AADInternalstool
G1053on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.