logo

Storm-1977 targets education sector with password spraying, Microsoft warns

ID: 58d14b3e-3eec-5b97-9f90-eb91f55c7490

STIX ID: report--58d14b3e-3eec-5b97-9f90-eb91f55c7490

Feed Name: Security Affairs

Threat Score
65/100

Date Published: 2025-04-27

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft Threat Intelligence attributes a year-long password-spraying campaign against education-sector cloud tenants to a threat actor tracked as Storm-1977. The actor used AzureChecker.exe to download AES-encrypted target lists and validate credentials (including supplied accounts.txt), leading to at least one breach where a guest account created a resource group and more than 200 containers for cryptomining; the report warns of broader risks to containerized environments and lists common threats and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.