Thecyberexpress
Storm-2949 Cyberattack Targets Microsoft 365 and Azure Data
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Microsoft has reported a significant cyberattack by the threat actor Storm-2949, which exploited Microsoft Entra ID accounts to conduct a large-scale data theft from Microsoft 365 and Azure environments. The attack involved social engineering tactics to compromise high-privilege user accounts, using the Self-Service Password Reset (SSPR) process to reset passwords and bypass multi-factor authentication (MFA). Once inside, the attackers utilized Microsoft Graph API and custom Python scripts to enumerate users and access sensitive data, including VPN configurations and operational files. They expanded their reach into Azure infrastructure, compromising virtual machines, storage accounts, and Azure Key Vaults to extract critical secrets and credentials. The attack exemplifies a shift towards using legitimate cloud management features for malicious purposes, avoiding traditional malware deployment. Microsoft has confirmed that multiple organizations have been affected, with ongoing investigations into the full scope of the breach.
Key Points: • Storm-2949 exploited Microsoft Entra ID accounts to steal sensitive data from Microsoft 365 and Azure. • Attackers used social engineering to bypass MFA and reset passwords of high-privilege accounts. • The breach involved extensive data theft, including VPN configurations and Azure Key Vault secrets.