en
  • de
Baggenstos Firmen Logo
  • Services
    • Managed Services
      • Azure Backup
      • Azure Site Recovery
      • Azure Billing
      • Managed Azure Workplace
      • Operation Care
    • Consulting Services
      • Azure Landingzone
      • Coding-as-a-Service
      • Cloud Readiness Workshop
      • Security Assessment
      • Lift and Shift
      • Azure AVD Assessment
      • Azure Migration & Modernization
      • Modern Workplace
  • Technology
    • Azure
    • Microsoft 365 & Co
    • Microsoft Copilot
    • Videos: briefly explained
    • Cloud-PC
    • Security: Overview
  • References
  • Company
    • About
    • 100 years Baggenstos
      • Videos: briefly explained
      • 100 Jahre in Bildern
      • 100 years Baggenstos
    • Team
    • Why Baggenstos
    • Certifications
      • Certifications
    • Baggiwood
  • News
    • Events
    • News
    • Webinars
    • Videos: briefly explained
  • Career
  • Contact
Baggenstos Firmen Logo
  • Services
    • Managed Services
      • Azure Backup
      • Azure Site Recovery
      • Azure Billing
      • Managed Azure Workplace
      • Operation Care
    • Consulting Services
      • Azure Landingzone
      • Coding-as-a-Service
      • Cloud Readiness Workshop
      • Security Assessment
      • Lift and Shift
      • Azure AVD Assessment
      • Azure Migration & Modernization
      • Modern Workplace
  • Technology
    • Azure
    • Microsoft 365 & Co
    • Microsoft Copilot
    • Videos: briefly explained
    • Cloud-PC
    • Security: Overview
  • References
  • Company
    • About
    • 100 years Baggenstos
      • Videos: briefly explained
      • 100 Jahre in Bildern
      • 100 years Baggenstos
    • Team
    • Why Baggenstos
    • Certifications
      • Certifications
    • Baggiwood
  • News
    • Events
    • News
    • Webinars
    • Videos: briefly explained
  • Career
  • Contact
en
  • de
Security for Your Backups
03.09.2025

A financially motivated assault on Azure instances

A ransomware group known as Storm-0501 is currently targeting cloud workloads, with a particular focus on Azure. Here’s how to protect your environment.

Both Microsoft and Baggenstos warn that Storm-0501 operators exfiltrate data, encrypt originals, and destroy backups. Their ultimate goal: extortion.

The group has been active for years, with documented attacks against US school districts and healthcare providers. More recently, Storm-0501 has shifted tactics, moving away from local endpoints to attack hybrid cloud infrastructures. Their cloud-native ransomware rapidly siphons off large volumes of data, rendering traditional malware redundant.

Anatomy of an attack

An incident in autumn 2024 illustrates their modus operandi. Attackers compromised Active Directory and Microsoft Entra ID to obtain global administrator rights. They then implanted backdoors in Entra ID tenant configurations via federated domains. In some cases, they deployed on-premises ransomware to encrypt endpoints and servers.

Microsoft's security blog details one such case: the victim had fragmented Microsoft Defender deployments across subsidiaries. An Entra Connect Sync server without endpoint protection became the pivot point. Attackers harvested password hashes, attempted multiple privileged account logins, and ultimately succeeded. With a global admin account, they gained direct access to the Azure portal.

Defending against Azure account takeover

Microsoft has introduced mitigations: 

  • A change in Microsoft Entra ID restricts permissions for the Directory Synchronization Accounts (DSA) role, reducing opportunities for privilege escalation.
  • The May 2025 release of Entra Connect introduces modern authentication with application-based options (currently in public preview).
  • Enabling the Trusted Platform Module (TPM) on Entra Connect Sync servers helps secure credentials and cryptographic keys, mitigating Storm-0501’s credential extraction techniques.

 

How Baggenstos can help

Baggenstos supports organisations in securing their Azure environments. This requires a holistic security posture that protects on-premises infrastructure, cloud identities, and workloads.

«Baggenstos provides secure predefined baselines,» explains Cloud Solution Architect Sven Heeb. «We apply the latest security standards, including ransomware-resilient backups with Azure Resource Guard.»

The latest wave of attacks highlights the need for robust design and implementation of hybrid cloud environments. As Heeb stresses:

«Hybrid clouds deliver productivity gains, but they also introduce new attack vectors. Security must be built in from the ground up.»

Microsoft Threat Intelligence Blog on Storm-0501

Azure Ressource Guard

Book backup security now

Booking request Learn more
Previous article

b.secure: Datenschützer an dei...

Next article

Webinar Prompt Power: KI-Werkz...

Newsletter

Support

  • Services
    • Managed Services
      • Operation Care
      • Managed Azure Workplace
      • Azure Billing
      • Azure Backup
      • Azure Site Recovery
    • Consulting Services
      • Azure Migration & Modernization
      • Lift and Shift
      • Azure AVD Assessment
      • Coding-as-a-Service
      • Cloud Readiness Workshop
      • Azure Landingzone
      • Security Assessment
      • Modern Workplace
  • Technology
    • Azure
    • Microsoft Copilot
    • Security: Overview
    • Videos: briefly explained
    • Microsoft 365 & Co
    • Cloud-PC
  • References
  • Company
    • About
    • 100 years Baggenstos
      • 100 years Baggenstos
      • 100 Jahre in Bildern
      • Videos: briefly explained
    • Team
    • Why Baggenstos
    • Certifications
      • Certifications
    • Baggiwood
  • News
    • Webinars
    • Videos: briefly explained
  • Career
  • Data Protection
  • Terms

Folgen Sie uns auf: LinkedIn / Youtube / Instagram / Facebook / X

 
© 2025

A. Baggenstos & Co. AG