logo

Microsoft Details Storm-2949 Cloud Attack on Azure and Microsoft 365

ID: b388553a-ceab-5af7-a631-ef98b8682b55

STIX ID: report--b388553a-ceab-5af7-a631-ef98b8682b55

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Ashish Khaitan

...
...

Microsoft Threat Intelligence details a Storm-2949 campaign that abused MFA reset social engineering to hijack privileged Microsoft 365/Entra identities, then leveraged Azure management-plane features (Key Vault access, App Service publish profiles/Kudu, Storage/SQL management operations, VM extensions and Run Command) and legitimate administration tools (OAuth and secret-based auth, ScreenConnect) to gain persistent access and exfiltrate sensitive data from production cloud resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.