logo

Hackers Exploit Azure RBAC to Steal Key Vault Secrets

ID: 6d98ec1d-8234-516e-b215-5f11ace53dce

STIX ID: report--6d98ec1d-8234-516e-b215-5f11ace53dce

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Mayura Kathir

...
...

Storm-2949 executed a multi-stage cloud takeover by socially engineering Entra ID users to bypass MFA and reset credentials, performing directory reconnaissance via Microsoft Graph, and abusing Azure RBAC and Key Vault Owner permissions to extract secrets and access production resources; the attackers exfiltrated data from Microsoft 365, storage accounts, and databases, used VM extensions and remote management tools for persistence, and leveraged legitimate Microsoft cloud features to blend in, with several egress IPs and a ScreenConnect instance listed as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.