Microsoft says Storm-2949 used identity abuse to breach Azure cloud

Microsoft Threat Intelligence says the group Storm-2949 used social engineering and abused password reset flows to take over Microsoft Entra ID accounts, then exfiltrated data from Microsoft 365 and Azure resources. The attack spread across App Service, Key Vault, Storage, SQL, and virtual machines, according to Microsoft.

Microsoft says Storm-2949 used identity abuse to breach Azure cloud

Microsoft Threat Intelligence says a threat actor it tracks as Storm-2949 turned a compromised identity into broad access across a victim’s cloud environment, then used that access to steal data from Microsoft 365 and Azure-hosted systems.

According to Microsoft, the campaign started with targeted social engineering against specific users to obtain Microsoft Entra ID credentials. The attackers appear to have abused Microsoft’s Self-Service Password Reset, or SSPR, process by initiating resets on behalf of victims and then persuading them to approve multifactor authentication prompts that looked legitimate.

⚡ New to this?

This matters because it shows how one stolen cloud identity can open access to a lot more than a single account. Microsoft Entra ID is a login and identity system for Microsoft cloud services, and Azure RBAC is the permission system that decides who can manage cloud resources. If those are abused, attackers can reach mail, storage, databases, and virtual machines without needing malware on every device.

🦞 OpenClaw angle

If you run self-hosted agents or automation that touches cloud APIs, separate human admin identities from machine identities and give each one the smallest set of permissions possible. Do not let one service principal or token control Key Vault, storage, and VM management at the same time. Also log and alert on password resets, MFA method changes, Graph API enumeration, and any use of cloud management actions like firewall edits or VM Run Command, because those are the kinds of steps that turned identity access into cloud control here.

Microsoft said the attackers used that access to reset passwords, remove existing authentication methods, and then register Microsoft Authenticator on their own devices. That gave Storm-2949 persistent access and blocked the real users from signing in.

The company said the group repeated that technique across multiple accounts, including IT staff and senior leaders. Microsoft assessed that this pattern showed a deliberate phishing scheme aimed at users with access to high-value systems.

Once inside, the attackers used Microsoft Graph API with a custom Python script to enumerate users, applications, and service principals in the tenant. Microsoft said they searched for accounts based on name patterns and role attributes, likely to identify privileged identities and other valuable targets.

Storm-2949 also tried to add credentials to a compromised service principal, according to Microsoft, but that attempt failed because of insufficient permissions. Even so, the attackers kept mapping application-level access paths and compromised three more cloud user accounts using the same social engineering approach.

Microsoft said the group then moved into Microsoft 365 data theft, focusing on OneDrive and SharePoint. In one case, the attackers downloaded thousands of files in a single action from OneDrive to their own infrastructure.

The files they targeted included IT documents about VPN configurations and remote access procedures, which Microsoft said suggests the attackers were looking for ways to move further into endpoint networks from the cloud account compromise. The company said the pattern repeated across the compromised users because each account had access to different folders and shared directories.

From there, Storm-2949 shifted toward Azure subscriptions tied to production systems. Microsoft said the attackers had privileged custom Azure role-based access control, or RBAC, permissions across several subscriptions and focused on App Service, Key Vault, Storage accounts, SQL databases, and virtual machines.

One target was a production Azure App Service web app that held sensitive data. After failed attempts to reach it directly, Microsoft said the attackers used the management-plane operation microsoft.Web/sites/publishxml/action to retrieve publishing profiles for related apps. Those profiles can include credentials for FTP, Web Deploy, and the Kudu management console, a built-in administrative interface for Azure App Service.

Microsoft said the attackers successfully compromised several auxiliary web apps, but not the main production app they were after. They then pivoted to Azure Key Vault, where one compromised user had Owner rights over a specific vault.

According to Microsoft, the attackers changed Key Vault access settings and accessed dozens of secrets in about four minutes. Those secrets included database connection strings and identity credentials, and Microsoft believes some of them enabled access to the primary production web app. After authenticating, the attackers changed its password and began exfiltrating data.

The attackers also manipulated Azure SQL firewall rules with microsoft.sql/servers/firewallrules/write so they could connect to a server using credentials retrieved from Key Vault. Microsoft said they later deleted the modified firewall rules, which fits defense evasion.

For Azure Storage, the group changed network access settings and used microsoft.Storage/storageAccounts/listkeys/action to obtain shared access signature tokens and account keys. Microsoft said they then used a custom Python script and the Azure SDK for Storage to enumerate and download blobs directly to their own endpoint over multiple days.

The campaign also reached virtual machines. Microsoft said Storm-2949 used the VMAccess extension to create a new local administrator account and the Run Command feature to run PowerShell scripts. Those scripts tried to weaken Microsoft Defender Antivirus, install the ScreenConnect remote monitoring and management tool, and clear logs and other local artifacts.

Microsoft said the attackers used ScreenConnect to run commands across several compromised devices, collect system and domain information, harvest .pfx certificate files, and scan for password-related strings in file shares. The company said some of those actions were aimed at credential harvesting and could support further access, but the endpoints were not the main exfiltration path.

Microsoft said Defender generated multiple alerts during the incident and correlated them into unified incidents across identity, cloud, and endpoint activity. The company argued that this kind of cross-domain visibility helped analysts reconstruct the attack chain from the initial account takeover to cloud and endpoint compromise.

Source: Microsoft Security Blog ↗

More from Security News