logo

SIM swapping to serial port abuse (Incident)

ID: 441ab73d-0818-51a1-a1ad-2c7d2d370ff2

STIX ID: report--441ab73d-0818-51a1-a1ad-2c7d2d370ff2

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2023-05-16

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Mandiant observed UNC3944 using SMS phishing and SIM swapping to seize privileged Azure administrator accounts, then leveraging Azure Serial Console and VM Extensions to execute PowerShell, install remote management tools, and conduct tenant-wide reconnaissance and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.