logo

State-Sponsored Actors Operationalize ROADtools Framework in Cloud Campaigns

ID: 18073153-2be4-5690-b1d3-c91a8c6837c6

STIX ID: report--18073153-2be4-5690-b1d3-c91a8c6837c6

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Ddos

...
...

This report analyzes the ROADtools cloud attack toolkit, which attackers use to enumerate Entra ID, manipulate authentication tokens (via a module called roadtx), register rogue devices, and replay session assets to bypass MFA and maintain persistence. The toolkit leverages legitimate Microsoft APIs to blend into normal traffic and has been observed in campaigns attributed to APT groups (e.g., Cloaked Ursa, Curious Serpens) and a phishing wave in early 2025; the report recommends updating hunting queries, monitoring unusual user-agent strings and unauthorized device registrations, and improving visibility of cloud identity transactions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.