Midnight Blizzard: Guidance for responders on nation-state attack
ID: b8936518-1622-5e0f-8986-4fc998e06c4f
STIX ID: report--b8936518-1622-5e0f-8986-4fc998e06c4f
Feed Name: Microsoft Security
*Executive summary:* Microsoft detected and investigated a nation-state intrusion by the Russian-linked actor Midnight Blizzard (NOBELIUM) that used targeted password-spray attacks against a legacy non-production tenant lacking MFA, created and abused OAuth applications (including granting full_access_as_app and ApplicationImpersonation) to access Exchange Online via Exchange Web Services for email collection, and routed activity through residential proxy infrastructure; the report details observed techniques, detection/hunting queries, Entra/Defender/Sentinel alerts, and recommended defenses to protect and remediate similar compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
