Azure Account Hijack via Stolen Tokens (Campaign)
ID: b1181d51-e438-5edd-be7f-b797070307bb
STIX ID: report--b1181d51-e438-5edd-be7f-b797070307bb
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-07-08
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
A Darktrace customer’s Azure environment was compromised after attackers obtained access tokens from cracked software linked to an external consultant; the attacker used those tokens to modify security rules to permit inbound SSH, deployed a rogue VM for persistent access and resource hijacking, and later registered MFA and sent an anomalous collaboration invite to an external Gmail address.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
