Ransomware gang using stolen Microsoft Entra ID creds to bust into the cloud
ID: b6cff3fa-3407-59e3-ad17-58b434451d75
STIX ID: report--b6cff3fa-3407-59e3-ad17-58b434451d75
Feed Name: The Register (Security)
Threat Score
Microsoft warns that Storm-0501, an emerging financially motivated group active since 2021, is pivoting from on-prem to hybrid cloud environments by stealing Entra Connect credentials and compromising unprotected cloud admin accounts to implant backdoors and enable data theft and ransomware (recently observed using the Embargo payload); Microsoft provides detection guidance and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
