logo

Amazon disrupts Russian APT29 hackers targeting Microsoft 365

ID: bda11ea8-f960-50ec-9c7f-ba41db0dbb4c

STIX ID: report--bda11ea8-f960-50ec-9c7f-ba41db0dbb4c

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-09-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers disrupted a watering-hole campaign attributed to Russian APT29 (Midnight Blizzard) that injected obfuscated JavaScript into compromised websites to randomly redirect visitors to attacker-controlled domains mimicking Cloudflare verification pages. The fake pages fed victims into a malicious Microsoft device code authentication flow to get them to authorize attacker-controlled devices for access to Microsoft 365 accounts; Amazon, Cloudflare, and Microsoft collaborated to isolate and take down the infrastructure used.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.