Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Storm-0501 Hybrid Cloud Attacks 2024: How Stolen Entra…
Breach analysis Incident: 26 Sep 2024

Storm-0501 Hybrid Cloud Attacks 2024: How Stolen Entra Connect Sync Credentials Carried Ransomware Operators Into the Cloud

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
Category: NHI
On this page

On 26 September 2024, Microsoft Threat Intelligence described how Storm-0501, a financially motivated ransomware affiliate active since at least 2021, had extended its attacks from on-premises networks into Microsoft Entra ID. In a recent campaign against US organisations in government, manufacturing, transportation and law enforcement, the group broke in through stolen credentials or known flaws in Zoho ManageEngine, Citrix NetScaler and Adobe ColdFusion, stole more credentials and took over domain controllers. It then went after the identities that connect on-premises Active Directory to the cloud. Microsoft assessed with high confidence that the group located Microsoft Entra Connect Sync servers and extracted the plain text credentials of the synchronisation accounts, which can set or change the Entra ID password of any hybrid account. It also used on-premises admin accounts whose cloud equivalents had no MFA. Once in the cloud it planted a federated-domain backdoor, stole data and, in some cases, deployed Embargo ransomware. Microsoft did not name the victims.

Key takeaways

  • Storm-0501 is "the latest threat actor observed to exploit weak credentials and over-privileged accounts" to move from on-premises networks to the cloud, according to Microsoft's 26 September 2024 report.
  • The group extracted the plain text credentials of Entra Connect Sync accounts, the service accounts that synchronise Active Directory with Entra ID. Those credentials can change the cloud password of any synchronised account.
  • A second route used a compromised Domain Admin whose matching Entra ID account had MFA disabled and held the Global Administrator role.
  • In the cloud, the group added a federated domain with AADInternals, letting it forge tokens to impersonate any user and bypass MFA. Some intrusions ended in Embargo ransomware; others stopped at the backdoor.
  • The identity lesson: hybrid identity sync accounts are Tier 0 service accounts, and their servers need the same protection as domain controllers, because whoever holds them controls the cloud tenant.

At a glance

OrganisationsUnnamed US organisations in government, manufacturing, transportation and law enforcement, according to Microsoft; the group was also seen targeting US hospitals
WhenStorm-0501 active since at least 2021; hybrid cloud campaign reported by Microsoft on 26 September 2024
AttackerStorm-0501, a financially motivated cybercriminal group and ransomware-as-a-service affiliate (Hive, BlackCat, Hunters International, LockBit, Embargo), as tracked by Microsoft
Entry pointStolen or weak credentials, sometimes via access brokers, and exploitation of CVE-2022-47966 (Zoho ManageEngine), CVE-2023-4966 (Citrix NetScaler) and a ColdFusion 2016 server
Identities abusedMicrosoft Entra Connect Sync accounts (on-premises and cloud); Domain Admin accounts; a cloud Global Administrator account without MFA; forged SAML tokens through a rogue federated domain
ImpactDomain compromise, data theft, cloud persistence and, in some cases, Embargo ransomware; victims not named
CategoryNHI. Incident class: confirmed NHI breach (stolen hybrid identity sync service account credentials used to take over cloud tenants)

What happened

Microsoft tracks Storm-0501 as "a financially motivated cybercriminal group" that uses commodity and open-source tools. It first appeared in 2021 deploying Sabbath ransomware against US school districts, then worked as an affiliate for several ransomware-as-a-service programmes. In the campaign Microsoft described in September 2024, access came from brokers tracked as Storm-0249 and Storm-0900, from stolen or weak credentials, or from exploiting known flaws in internet-facing servers: CVE-2022-47966 in Zoho ManageEngine, CVE-2023-4966 (CitrixBleed) in Citrix NetScaler, and a ColdFusion 2016 application, possibly through CVE-2023-29300 or CVE-2023-38203.

Inside the network the group harvested credentials with Impacket's SecretsDump, extracted secrets from KeePass, and moved laterally with Cobalt Strike, often reaching Domain Admin rights and the domain controllers. It installed remote management tools including AnyDesk, NinjaOne and Level.io for persistence, tampered with security products and copied data out with Rclone to public cloud storage such as MegaSync.

The step that set this campaign apart was the move to the cloud. Microsoft Entra Connect synchronises on-premises Active Directory with Entra ID using two service accounts: an on-premises account with the prefix MSOL_ and a cloud account assigned the Directory Synchronization Accounts role. Microsoft said it could "assess with high confidence" that the threat actor "specifically located Microsoft Entra Connect Sync servers" and "managed to extract the plain text credentials" of those accounts, helped by earlier credential theft and theft of DPAPI keys. Microsoft warned, as quoted by The Register, that this "can allow the threat actor to set or change Microsoft Entra ID passwords of any hybrid account". In another case, a compromised Domain Admin account had a cloud counterpart with MFA disabled and the Global Administrator role. Without MFA or Conditional Access, resetting the on-premises password was enough to take the cloud account.

With cloud admin access, the group created a new federated domain in the victim's tenant using the AADInternals tool. Microsoft said the SAML tokens this allowed it to forge "can be used to impersonate any user in the organization and bypass MFA", and it saw the group use them to sign in to Office 365. Some intrusions ended with Embargo ransomware pushed through a Group Policy scheduled task named SysUpdate; others stopped once the backdoor was in place. Microsoft has since restricted the permissions of the Directory Synchronization Accounts role. In an August 2025 update, it said the group had moved further toward cloud-based ransomware that relies on cloud functions rather than malware.

Timeline

DateEvent
2021Storm-0501 first appears, deploying Sabbath ransomware against US school districts, according to Microsoft.
2024The group runs a campaign against US organisations that moves from on-premises networks into Entra ID.
26 September 2024Microsoft Threat Intelligence publishes its report on Storm-0501's hybrid cloud attacks.
27 September 2024The Register reports the findings, noting Microsoft's comparison with Octo Tempest and Manatee Tempest.
30 September 2024Help Net Security reports on the Entra Connect Sync abuse.
27 August 2025Microsoft updates its report, saying Storm-0501 has shifted toward cloud-based ransomware.

How it happened: the identity attack path

  1. Initial access. Stolen or weak credentials, access brokers, or exploitation of unpatched internet-facing servers gave a foothold, often with local admin rights.
  2. Credential harvesting on-premises. SecretsDump, KeePass extraction and brute force yielded more credentials, leading to Domain Admin and the domain controllers.
  3. Sync service account stolen. The group located Entra Connect Sync servers and extracted the plain text credentials of the on-premises and cloud synchronisation accounts.
  4. Pivot to the cloud. The sync credentials, or a Domain Admin whose cloud twin had no MFA and held Global Administrator, gave control of cloud accounts.
  5. Persistence by federation. A rogue federated domain let the group forge tokens for any user and bypass MFA.
  6. Theft and extortion. Data was exfiltrated and, in some cases, Embargo ransomware was deployed through Group Policy.

Impact

  • Confirmed by Microsoft: compromise of on-premises domains and Entra ID tenants at US organisations, data theft, cloud backdoors and Embargo ransomware in some cases.
  • Not disclosed: victim names, number of victims and amount of data stolen.
  • Potential: any organisation with Entra Connect Sync servers that are not protected as Tier 0 assets, or cloud admin accounts without MFA, is exposed to the same path.
  • Response: Microsoft restricted permissions on the Directory Synchronization Accounts role and published detection and hunting guidance.

What this means for NHI governance

The pivotal identities in Storm-0501's campaign were service accounts. Entra Connect Sync accounts exist so that a server can update Entra ID on behalf of on-premises Active Directory, without any person signing in. Because their job is to write identity data into the cloud, they hold powers that few humans have, including the ability to set passwords for synchronised accounts. Their credentials sit on a server on-premises, so an attacker who wins the domain can usually win the sync server too, and with it the cloud.

This is the same lesson as Storm-2949 in 2026 and Midnight Blizzard in 2024: the bridges between environments, whether sync accounts, test tenants or OAuth apps, are where attackers cross. Treat sync servers as Tier 0, keep cloud admin accounts cloud-only with phishing-resistant MFA, and watch for new federated domains. Our Active Directory and Entra ID Hardening Guide and Service Account Security Guide cover these controls.

Recommendations

  • Protect Entra Connect Sync servers as Tier 0. Restrict who can log on to them, monitor them like domain controllers and keep them patched. See our Active Directory and Entra ID Hardening Guide.
  • Treat sync accounts as privileged service accounts. Inventory them, alert on their use from anywhere but the sync server, and rotate their credentials after any domain compromise. See our Service Account Security Guide.
  • Separate cloud admin accounts from on-premises accounts. Use cloud-only Global Administrator accounts with phishing-resistant MFA, so a Domain Admin compromise does not carry into the cloud. See our Privileged Access Management Guide.
  • Enforce MFA and Conditional Access for every privileged identity. Microsoft found at least one Global Administrator without MFA. See our MFA Guide.
  • Alert on new federated domains and federation changes. A new federation trust is a backdoor that bypasses MFA. See our ITDR Guide.
  • Patch internet-facing servers promptly. Fixes for the CVEs Microsoft named, including CitrixBleed, were published before its September 2024 report.

Frequently asked questions

What is Storm-0501?

Storm-0501 is Microsoft's name for a financially motivated cybercriminal group active since at least 2021. It has worked as an affiliate for ransomware programmes including Hive, BlackCat, LockBit, Hunters International and Embargo, and in 2024 extended its attacks from on-premises networks into Entra ID.

How did Storm-0501 abuse Entra Connect Sync?

After taking over the on-premises domain, the group located Entra Connect Sync servers and extracted the plain text credentials of the synchronisation accounts. Microsoft says those credentials can be used to set or change the Entra ID password of any hybrid account, giving access to cloud accounts.

How can organisations defend against Storm-0501?

Protect sync servers like domain controllers, use cloud-only admin accounts with phishing-resistant MFA, enforce Conditional Access, alert on new federated domains and patch internet-facing servers. Microsoft has also restricted the Directory Synchronization Accounts role's permissions.

Storm-2949 Azure Attack 2026 · Microsoft Midnight Blizzard Breach 2024 · CitrixBleed 2023 · Active Directory and Entra ID Hardening Guide · Service Account Security Guide

How NHI Mgmt Group can help

Hybrid identity rests on a handful of powerful service accounts that are easy to overlook. We help organisations find them, protect them as Tier 0 and detect their misuse. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org