logo

Ransomware gang using stolen Microsoft Entra ID creds to bust into the cloud

ID: b6cff3fa-3407-59e3-ad17-58b434451d75

STIX ID: report--b6cff3fa-3407-59e3-ad17-58b434451d75

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-09-27

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Microsoft warns that Storm-0501, an emerging financially motivated group active since 2021, is pivoting from on-prem to hybrid cloud environments by stealing Entra Connect credentials and compromising unprotected cloud admin accounts to implant backdoors and enable data theft and ransomware (recently observed using the Embargo payload); Microsoft provides detection guidance and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.