Storm-1977 targets education sector with password spraying, Microsoft warns
ID: 58d14b3e-3eec-5b97-9f90-eb91f55c7490
STIX ID: report--58d14b3e-3eec-5b97-9f90-eb91f55c7490
Feed Name: Security Affairs
Microsoft Threat Intelligence attributes a year-long password-spraying campaign against education-sector cloud tenants to a threat actor tracked as Storm-1977. The actor used AzureChecker.exe to download AES-encrypted target lists and validate credentials (including supplied accounts.txt), leading to at least one breach where a guest account created a resource group and more than 200 containers for cryptomining; the report warns of broader risks to containerized environments and lists common threats and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
