The intruder is in the house: Storm-0501 attacked Azure, stole data, demanded payment via Teams
ID: 8ef9236e-e237-58ac-a7ae-51dfab916ff8
STIX ID: report--8ef9236e-e237-58ac-a7ae-51dfab916ff8
Feed Name: The Register (Security)
Microsoft tracked a financially motivated group named Storm-0501 that shifted from traditional endpoint ransomware to cloud-native attacks: they compromised Entra Connect servers, used DCSync and credential theft to escalate to Entra global admin, registered a malicious federated tenant and obtained broad Azure privileges, then exfiltrated and deleted data in the victim's Azure environment and extorted the organization via a compromised Teams account; Microsoft provides mitigation guidance including enforcing MFA, least privilege, and protecting sync servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
