logo

Microsoft Warns of Widening APT29 Espionage Attacks Targeting Global Orgs

ID: 43e98db9-a765-5cc2-87b2-4bf2fd014d51

STIX ID: report--43e98db9-a765-5cc2-87b2-4bf2fd014d51

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-01-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft reported that Russian state-sponsored APT29 (aka Midnight Blizzard/Cozy Bear) executed a wide espionage campaign affecting Microsoft and other organizations, including HPE, by using password-spray attacks against legacy accounts, compromising and weaponizing OAuth applications to obtain Office 365 Exchange Online access, and leveraging distributed residential proxies to obfuscate activity and exfiltrate email data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.