Sloppy Entra ID Credentials Attract Hybrid Cloud Ransomware
ID: d6942628-30cb-57d2-89b4-a316574287f3
STIX ID: report--d6942628-30cb-57d2-89b4-a316574287f3
Feed Name: Dark Reading
Date Published: 2024-09-30
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Microsoft Threat Intelligence details Storm-0501, a ransomware-affiliate group active since 2021 that has shifted from purchasing access to exploiting weak credentials and overprivileged accounts in hybrid cloud environments. The actors located Microsoft Entra Connect sync servers, extracted clear-text sync account credentials, and used them (or compromised Domain Admin accounts) to obtain access tokens to Microsoft Graph, change Entra ID passwords, exfiltrate data, establish persistent backdoors, and deploy Embargo ransomware across targeted organizations (including schools, hospitals, and law enforcement). Microsoft and other experts recommend zero-trust, least-privilege, MFA enforcement, centralized endpoint management, timely patching, and enhanced monitoring to mitigate these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
