Microsoft reveals how hackers breached its Exchange Online accounts
ID: ca74d01c-6e3a-5369-ae45-355df6597985
STIX ID: report--ca74d01c-6e3a-5369-ae45-355df6597985
Feed Name: Bleeping Computer
Microsoft confirmed that the Russian-linked APT group Midnight Blizzard (Nobelium/APT29) compromised a legacy non-production Microsoft account in November 2023 using password-spray attacks and residential proxies, abused OAuth application permissions to create malicious apps and obtain Office 365 full_access_as_app to access and exfiltrate corporate mailboxes, and that similar techniques impacted other organizations (HPE among them); Microsoft published detection and hunting guidance focused on identity, OAuth activity, and Exchange Web Services telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
