CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4538

As cited

Copy frozen at (site build).

ransomware

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Tenable One Cloud Exposure uses AI-powered detection to track Storm-0501, a financially motivated cybercrime group that has shifted from endpoint ransomware to compromising entire Azure cloud tenants by hijacking administrative identities and disabling defensive controls. The tool aggregates Azure activity logs into threat stories mapped to the MITRE ATT&CK framework, enabling defenders to rapidly identify breach points, revoke compromised credentials, restore deleted resource locks and backups, and contain attacks across the cloud infrastructure. Cloud detection and response (CDR) capabilities provide the contextual visibility needed to detect modern cloud ransomware campaigns that exploit the cloud control plane rather than local endpoints.

Why it matters: Azure-using organizations should assess whether they can detect Storm-0501's tactics of disabling immutability policies, backup systems, and resource locks in real time; cloud ransomware now requires cloud-native detection beyond endpoint monitoring to prevent total tenant compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Tenable One’s Cloud Exposure uses artificial intelligence (AI)-powered threat stories to detect the tactics of the cybercrime group Storm-0501, which conducts Azure‑based ransomware by hijacking administrative identities and dismantling cloud defenses. The platform correlates Azure activity logs into a unified timeline that maps the group’s techniques to the MITRE ATT&CK framework, enabling rapid identification and containment of attacks. By revealing configuration changes such as deleted resource locks or immutability policies, it helps defenders restore protections before data is encrypted or exfiltrated.

Why it matters: Azure administrators and security teams using Tenable One should monitor for Storm‑0501 tactics and immediately revoke compromised Entra ID global administrator sessions to prevent tenant‑wide ransomware.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Tenable One’s Cloud Exposure uses artificial intelligence (AI)-powered threat stories to detect the tactics of the cybercrime group Storm-0501, which conducts Azure‑based ransomware by hijacking administrative identities and dismantling cloud defenses. The platform correlates Azure activity logs into a unified timeline that maps the group’s techniques to the MITRE ATT&CK framework, enabling rapid identification and containment of attacks. By revealing configuration changes such as deleted resource locks or immutability policies, it helps defenders restore protections before data is encrypted or exfiltrated.

Why it matters: Azure administrators and security teams using Tenable One should monitor for Storm‑0501 tactics and immediately revoke compromised Entra ID global administrator sessions to prevent tenant‑wide ransomware.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary