Microsoft email exfiltration by Nobelium (Incident)
ID: c47ff769-410a-5a11-8e98-b582e01a3f0d
STIX ID: report--c47ff769-410a-5a11-8e98-b582e01a3f0d
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-01-19
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Microsoft disclosed that Nobelium conducted a targeted campaign beginning in late November 2023 that used low-volume password spraying against a legacy test account, routed traffic through a residential proxy network to avoid detection, and abused compromised and newly-created OAuth apps (including granting Office 365 Exchange Online full_access_as_app) to access and exfiltrate email from a small set of senior and sensitive Microsoft corporate mailboxes. Microsoft identified the activity via Exchange Web Services and audit logs and reported no evidence of access to customer environments, production systems, source code, or AI systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
