Summary
Key Points:
- Storm-2949 executed a sophisticated attack targeting cloud infrastructure, beginning with identity compromise to exfiltrate sensitive data from Microsoft 365 and Azure environments.
- The attack impacted various services including Microsoft Entra ID, Azure App Services, Key Vaults, and SQL databases, leading to significant data breaches and potential long-term access to sensitive assets.
- Organizations should enhance identity protection through MFA enforcement, implement robust monitoring across cloud resources, and leverage behavior-based detection tools like Microsoft Defender.
Technical Details: Storm-2949 exploited the Self-Service Password Reset (SSPR) process to gain unauthorized access to user accounts. They used automated API requests via Microsoft Graph API for directory discovery and manipulated Azure RBAC permissions to access critical resources.
MITRE ATT&CK Techniques:
- T1078 - Valid Accounts (Defense Evasion)
- T1190 - Exploit Public-Facing Application (Initial Access)
- T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
- T1059.001 - Command and Scripting Interpreter: PowerShell (Execution)
- T1566.001 - Phishing: Spearphishing Attachment (Initial Access)
IOCs Mentioned:
- 176.123.4[.]44
- 91.208.197[.]87
- 185.241.208[.]243
Join the discussion — sign up to comment, upvote, and save articles.