Storm-0501, a financially motivated cybercriminal group [1, 3].
Audit your Entra ID (formerly Azure AD) and other cloud environments for unauthorized access tokens or new, suspicious service principals created by the attacker [1, 4].
The executable is typically used for credential theft and lateral movement [1, 4].