State-Sponsored Actors Operationalize ROADtools Framework in Cloud Campaigns
ID: 18073153-2be4-5690-b1d3-c91a8c6837c6
STIX ID: report--18073153-2be4-5690-b1d3-c91a8c6837c6
Feed Name: securityonline.info
This report analyzes the ROADtools cloud attack toolkit, which attackers use to enumerate Entra ID, manipulate authentication tokens (via a module called roadtx), register rogue devices, and replay session assets to bypass MFA and maintain persistence. The toolkit leverages legitimate Microsoft APIs to blend into normal traffic and has been observed in campaigns attributed to APT groups (e.g., Cloaked Ursa, Curious Serpens) and a phishing wave in early 2025; the report recommends updating hunting queries, monitoring unusual user-agent strings and unauthorized device registrations, and improving visibility of cloud identity transactions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
