MuddyWater cloud destruction operation (Incident)
ID: c9fedf23-2af9-5ccb-80e1-b50607bba67c
STIX ID: report--c9fedf23-2af9-5ccb-80e1-b50607bba67c
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2023-04-07
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Microsoft attributed a destructive hybrid-cloud and on-premises operation to MuddyWater (also known as MERCURY or Mango Sandstorm) in collaboration with DarkBit; attackers reportedly exploited known unpatched vulnerabilities for initial access, moved laterally and used Azure AD Connect to pivot into Azure AD, then used highly privileged compromised credentials to perform mass destruction of resources across environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
