Tenable has published new Tenable One detections for Storm-0501, the Azure-focused ransomware crew it says is moving past endpoint encryption and into tenant-level control of cloud environments. The advisory says more rules are coming.
Storm-0501’s pattern is to gain high-privilege access and then use normal Azure controls against the tenant itself: resource locks, immutability settings, and backups can be turned off or removed. Once those recovery controls are gone, a cloud environment can be ransomed even if no workstation is visibly encrypted.
That puts the failure mode inside the control plane, not on an endpoint. If your recovery assumptions depend on Azure locks, immutable storage, or cloud backups, the durable risk is configuration tampering that makes those protections untrustworthy from within the tenant.