logo

Midnight Blizzard: Guidance for responders on nation-state attack

ID: b8936518-1622-5e0f-8986-4fc998e06c4f

STIX ID: report--b8936518-1622-5e0f-8986-4fc998e06c4f

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2024-01-26

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

*Executive summary:* Microsoft detected and investigated a nation-state intrusion by the Russian-linked actor Midnight Blizzard (NOBELIUM) that used targeted password-spray attacks against a legacy non-production tenant lacking MFA, created and abused OAuth applications (including granting full_access_as_app and ApplicationImpersonation) to access Exchange Online via Exchange Web Services for email collection, and routed activity through residential proxy infrastructure; the report details observed techniques, detection/hunting queries, Entra/Defender/Sentinel alerts, and recommended defenses to protect and remediate similar compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.