How Storm-2949 turned a compromised identity into a cloud-wide breach
ID: fb494d29-8bf6-5324-9aa5-f4add7e5db67
STIX ID: report--fb494d29-8bf6-5324-9aa5-f4add7e5db67
Feed Name: Microsoft Security
Date Published: 2026-05-18
Date Updated: 2026-05-22
Author: Microsoft Defender Security Research Team
Microsoft Threat Intelligence describes a sophisticated, identity-first campaign by Storm-2949 that leveraged social-engineered SSPR/MFA prompt abuse to gain Microsoft Entra ID credentials, then used Azure management-plane operations (Graph API, publish profile retrieval, Key Vault access, storage and SQL configuration changes, VM extensions/Run Command) and ScreenConnect RMM to move laterally and exfiltrate large volumes of sensitive data from Microsoft 365, Azure Storage, Azure SQL, and App Service environments; the report includes observed IOCs and detailed detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
