logo

Crooks hook hundreds of exec accounts after phishing in Azure C-suite pond

ID: 6b3e5a24-f335-540c-98c7-d70174efe014

STIX ID: report--6b3e5a24-f335-540c-98c7-d70174efe014

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-02-13

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Proofpoint researchers identified an ongoing targeted phishing campaign, active since November, that has produced hundreds of cloud account takeovers and compromised dozens of Azure environments. Attackers targeted C-suite and senior staff to steal sensitive files and credentials, abused mailboxes for lateral movement and phishing, manipulated MFA (registering authenticator apps and phone numbers), used mailbox rules and proxy services to evade detection, and leveraged localized ISPs to blend in. Recommended mitigations include monitoring for IoCs (notably a Linux Chrome user-agent), enforcing credential resets, hardening detection of ATOs, and implementing auto-remediation policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.