logo

Ongoing Azure Compromises Target Senior Execs, Microsoft 365 Apps

ID: 8f3ce06e-bb3e-51be-8bdd-c364374a7963

STIX ID: report--8f3ce06e-bb3e-51be-8bdd-c364374a7963

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-02-12

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers have observed an ongoing, sophisticated campaign targeting Microsoft Azure and Microsoft 365 corporate clouds that has compromised dozens of environments and hundreds of user accounts. Threat actors use highly tailored phishing lures to harvest credentials, register their own MFA methods, move laterally through Exchange Online to exfiltrate sensitive data and execute financial fraud, and create mailbox rules to hide their activity; a Linux user-agent has been identified as an indicator of compromise. Organizations are advised to enforce strong password hygiene, monitor for the identified IoC, and deploy auto-remediation policies to limit damage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.