← Back to news

How Storm-2949 turned a compromised identity into a cloud-wide breach

Microsoft Security Blog18/05/2026, 22:42
Read full article →

Summary

AI-Generated

Key Points:

  • Storm-2949 executed a sophisticated attack targeting cloud infrastructure, beginning with identity compromise to exfiltrate sensitive data from Microsoft 365 and Azure environments.
  • The attack impacted various services including Microsoft Entra ID, Azure App Services, Key Vaults, and SQL databases, leading to significant data breaches and potential long-term access to sensitive assets.
  • Organizations should enhance identity protection through MFA enforcement, implement robust monitoring across cloud resources, and leverage behavior-based detection tools like Microsoft Defender.

Technical Details: Storm-2949 exploited the Self-Service Password Reset (SSPR) process to gain unauthorized access to user accounts. They used automated API requests via Microsoft Graph API for directory discovery and manipulated Azure RBAC permissions to access critical resources.

MITRE ATT&CK Techniques:

  • T1078 - Valid Accounts (Defense Evasion)
  • T1190 - Exploit Public-Facing Application (Initial Access)
  • T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
  • T1059.001 - Command and Scripting Interpreter: PowerShell (Execution)
  • T1566.001 - Phishing: Spearphishing Attachment (Initial Access)

IOCs Mentioned:

  • 176.123.4[.]44
  • 91.208.197[.]87
  • 185.241.208[.]243

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.