Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Blog Artikel
01.06.2026
2 min read

Storm-0501: Protect Azure & Backups | Baggenstos

Symbolic image: three hackers in dark hoodies at laptops against a glowing red matrix background.

Das Wichtigste in Kürze

  • Storm-0501 ransomware attacks hybrid Azure cloud environments: takeover via Active Directory and Entra ID, data theft, encryption and destroyed backups. Microsoft has responded with restricted DSA permissions and a TPM requirement for Entra Connect Sync
  • Baggenstos protects with predefined security baselines and ransomware-proof backup via Azure Resource Guard

Both Microsoft and Baggenstos warn that Storm-0501 operators exfiltrate data, encrypt originals, and destroy backups. Their ultimate goal: extortion.

The group has been active for years, with documented attacks against US school districts and healthcare providers. More recently, Storm-0501 has shifted tactics, moving away from local endpoints to attack hybrid cloud infrastructures. Their cloud-native ransomware rapidly siphons off large volumes of data, rendering traditional malware redundant.

Anatomy of an attack

An incident in autumn 2024 illustrates their modus operandi. Attackers compromised Active Directory and Microsoft Entra ID to obtain global administrator rights. They then implanted backdoors in Entra ID tenant configurations via federated domains. In some cases, they deployed on-premises ransomware to encrypt endpoints and servers.

Microsoft's security blog details one such case: the victim had fragmented Microsoft Defender deployments across subsidiaries. An Entra Connect Sync server without endpoint protection became the pivot point. Attackers harvested password hashes, attempted multiple privileged account logins, and ultimately succeeded. With a global admin account, they gained direct access to the Azure portal.

Defending against Azure account takeover

Microsoft has introduced mitigations:

How Baggenstos can help

Baggenstos supports organisations in securing their Azure environments. This requires a holistic security posture that protects on-premises infrastructure, cloud identities, and workloads.

«Baggenstos provides secure predefined baselines,» explains Cloud Solution Architect Sven Heeb. «We apply the latest security standards, including ransomware-resilient backups with Azure Resource Guard

The latest wave of attacks highlights the need for robust design and implementation of hybrid cloud environments. As Heeb stresses:

«Hybrid clouds deliver productivity gains, but they also introduce new attack vectors. Security must be built in from the ground up.»

Microsoft Threat Intelligence Blog on Storm-0501

Azure Ressource Guard

No items found.

Share article

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund

Buch hier Sicherheit für deine Backups