# STORM-0501

> As of 2026-08-28, STORM-0501 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning ransomware. Also known as ALPHV, Noberus, BlackCat, Sphynx. ATT&CK coverage spans 33 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1490 (Inhibit System Recovery), T1685 (Disable or Modify Tools).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** RANSOMWARE
- **Also known as:** ALPHV, Noberus, BlackCat, Sphynx, Codefinger, ABCD ransomware
- **As of:** 2026-08-28

## ATT&CK techniques observed

33 techniques observed across 3 of 3 tracked threats. Tactics: Credential Access (4), Defense Impairment (4), Discovery (4), Impact (4), Persistence (4), Lateral Movement (3).

- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 3 of 3 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 3 of 3 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 3 of 3 tracked threats
- [T1484](https://intel.threadlinqs.com/technique/T1484) Domain or Tenant Policy Modification — Defense Impairment — observed in 2 of 3 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 2 of 3 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 2 of 3 tracked threats
- [T1526](https://intel.threadlinqs.com/technique/T1526) Cloud Service Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1530](https://intel.threadlinqs.com/technique/T1530) Data from Cloud Storage — Collection — observed in 2 of 3 tracked threats
- [T1537](https://intel.threadlinqs.com/technique/T1537) Transfer Data to Cloud Account — Exfiltration — observed in 2 of 3 tracked threats
- [T1580](https://intel.threadlinqs.com/technique/T1580) Cloud Infrastructure Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 2 of 3 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 1 of 3 tracked threats
- [T1003.006](https://intel.threadlinqs.com/technique/T1003.006) OS Credential Dumping: DCSync — Credential Access — observed in 1 of 3 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 1 of 3 tracked threats
- [T1021.006](https://intel.threadlinqs.com/technique/T1021.006) Windows Remote Management — Lateral Movement — observed in 1 of 3 tracked threats

## Tracked threats

- [Four Methods for Azure Blob Storage Ransomware: Client-Side Bulk Encryption, CPK, Encryption Scope, and CMK Abuse](https://intel.threadlinqs.com/threat/TL-2026-2191) — HIGH
- [Azure Blob Storage Ransomware: Four Storage-Encryption Abuse Methods (BlackCat/ALPHV, STORM-0501)](https://intel.threadlinqs.com/threat/TL-2026-0810) — HIGH
- [Human-Operated Ransomware via GPO Abuse — Domain-Wide Encryption Through Group Policy Weaponization](https://intel.threadlinqs.com/threat/TL-2026-0273) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/STORM-0501
