logo

Sloppy Entra ID Credentials Attract Hybrid Cloud Ransomware

ID: d6942628-30cb-57d2-89b4-a316574287f3

STIX ID: report--d6942628-30cb-57d2-89b4-a316574287f3

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-09-30

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

Microsoft Threat Intelligence details Storm-0501, a ransomware-affiliate group active since 2021 that has shifted from purchasing access to exploiting weak credentials and overprivileged accounts in hybrid cloud environments. The actors located Microsoft Entra Connect sync servers, extracted clear-text sync account credentials, and used them (or compromised Domain Admin accounts) to obtain access tokens to Microsoft Graph, change Entra ID passwords, exfiltrate data, establish persistent backdoors, and deploy Embargo ransomware across targeted organizations (including schools, hospitals, and law enforcement). Microsoft and other experts recommend zero-trust, least-privilege, MFA enforcement, centralized endpoint management, timely patching, and enhanced monitoring to mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.