Midnight Blizzard attack on Microsoft corporate environment: a detailed analysis, detections and recommendations
ID: ea6b42c3-02c5-5c31-850a-c4e99bed5616
STIX ID: report--ea6b42c3-02c5-5c31-850a-c4e99bed5616
Feed Name: Wiz Blog
Microsoft disclosed a Midnight Blizzard (Russian APT) intrusion that abused a legacy, non-production Entra ID account without MFA and a legacy OAuth application to obtain tenant-wide privileges from November 2023 to January 2024. The attackers used password-spray to compromise an account able to manage OAuth app secrets, used the test app's delegated MS Graph permissions (e.g., Directory.ReadWrite.All, RoleManagement.ReadWrite.Directory, AppRoleAssignment.ReadWrite.All) to create an admin user and provision malicious multi-tenant apps, then performed illicit admin-consent to grant full_access_as_app to those apps and used client_credentials tokens to access corporate mailboxes. The report includes step-by-step curl/az commands illustrating the flow, multiple Azure Log Analytics detection queries for suspicious app permission assignments, role assignments, and secret creation, and prescribes mitigations such as enforcing MFA, enabling Smart Lockout, and restricting user consent for third-party apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
