logo

How Storm-2949 turned a compromised identity into a cloud-wide breach

ID: fb494d29-8bf6-5324-9aa5-f4add7e5db67

STIX ID: report--fb494d29-8bf6-5324-9aa5-f4add7e5db67

Feed Name: Microsoft Security

Threat Score
85/100

Date Published: 2026-05-18

Date Updated: 2026-05-22

Author: Microsoft Defender Security Research Team

...
...

Microsoft Threat Intelligence describes a sophisticated, identity-first campaign by Storm-2949 that leveraged social-engineered SSPR/MFA prompt abuse to gain Microsoft Entra ID credentials, then used Azure management-plane operations (Graph API, publish profile retrieval, Key Vault access, storage and SQL configuration changes, VM extensions/Run Command) and ScreenConnect RMM to move laterally and exfiltrate large volumes of sensitive data from Microsoft 365, Azure Storage, Azure SQL, and App Service environments; the report includes observed IOCs and detailed detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.