logo

Storm-2949 Hijacks Azure Identity and Key Vaults in Catastrophic Cloud Campaign

ID: 1efd7f94-8311-5676-a745-9bc8c0fd347e

STIX ID: report--1efd7f94-8311-5676-a745-9bc8c0fd347e

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Ddos

...
...

A Microsoft Threat Intelligence report describes a sophisticated campaign by ‘Storm-2949’ that targeted cloud control planes via identity recovery abuse and social engineering to enroll attacker authenticator devices, enumerate directories with Graph API, exfiltrate sensitive OneDrive/SharePoint files, extract Key Vault secrets, manipulate RBAC and firewall rules to access databases and storage, and deploy VM extensions/RMM to persist and remove telemetry. The report warns that legitimate cloud management features were abused for lateral movement and data theft and recommends hardening recovery flows, enforcing phishing-resistant MFA and conditional access, disabling unneeded VM management extensions, and deploying behavioral analytics to detect administrative-plane anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.